#VU114225 Buffer overflow in Mozilla products - CVE-2025-9179
Published: August 19, 2025 / Updated: August 22, 2025
Mozilla Firefox
Firefox ESR
Firefox for Android
Firefox Focus for Android
Mozilla
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in GMP process when processing encrypted media. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
External links
- https://bugzilla.mozilla.org/show_bug.cgi?id=1979527
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-64/
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-67/
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-66/
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-65/