Incorrect calculation in Mozilla products - CVE-2025-8028
Published: July 22, 2025
Mozilla Firefox
Firefox ESR
Firefox for Android
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a WASM br_table instruction with a lot of entries can lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. A remote attacker can execute arbitrary code on the target system.
Note, the vulnerability affects ARM64 systems only.
How to mitigate CVE-2025-8028
Sources
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-57/
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-58/
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-59/
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-56/
- https://bugzilla.mozilla.org/show_bug.cgi?id=1971581