Cyber Security News

Firefox 141 Released With Fix for Multiple Vulnerabilities – Update Now

Mozilla has released Firefox 141 to address 17 security vulnerabilities, including several high-impact flaws that could potentially allow arbitrary code execution. 

The Mozilla Foundation Security Advisory, announced on July 22, 2025, urges users to update immediately to protect against these critical security issues.

Key Takeaways
1. Firefox 141 patches critical vulnerabilities that could allow code execution.
2. High-impact bugs affect core browser functions on 64-bit and ARM systems.
3. Mozilla urges immediate update to protect against these security risks.

JavaScript Engine and Memory Safety Flaws

The most severe vulnerabilities center around Firefox’s JavaScript engine and memory management systems. 

CVE-2025-8027 represents a particularly dangerous flaw where the IonMonkey-JIT compiler only wrote 32 bits of a 64-bit return value to the stack on 64-bit platforms, while the Baseline-JIT read the entire 64 bits. This mismatch could lead to unpredictable behavior and potential code execution.

Another critical issue, CVE-2025-8028, affects ARM64 systems where WebAssembly br_table instructions with numerous entries could cause label truncation, resulting in incorrect branch address calculations. 

The update also addresses multiple memory safety bugs tracked as CVE-2025-8044, CVE-2025-8034, CVE-2025-8040, and CVE-2025-8035, which Mozilla’s security team believes could be exploited for arbitrary code execution with sufficient effort.

Cross-Origin and Content Security Policy

Several vulnerabilities involved circumventing important web security mechanisms. CVE-2025-8036 allowed attackers to bypass Cross-Origin Resource Sharing (CORS) protections through DNS rebinding attacks, as Firefox cached CORS preflight responses across IP address changes. 

The browser also suffered from Content Security Policy (CSP) bypass issues, including CVE-2025-8032 where XSLT document loading failed to propagate source document CSP restrictions.

Authentication credentials faced exposure risk through CVE-2025-8031, where username:password combinations weren’t properly stripped from URLs in CSP reports, potentially leaking HTTP Basic Authentication credentials.

Additionally, CVE-2025-8029 enabled execution of javascript: URLs when embedded in object and embed tags, creating another attack vector.

CVETitleImpact
CVE-2025-8027JavaScript engine only wrote partial return value to stackHigh
CVE-2025-8028Large branch table could lead to truncated instructionHigh
CVE-2025-8044Memory safety bugs fixed in Firefox 141 and Thunderbird 141High
CVE-2025-8034Memory safety bugs fixed in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141High
CVE-2025-8040Memory safety bugs fixed in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141High
CVE-2025-8035Memory safety bugs fixed in Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141High
CVE-2025-8041Incorrect URL truncation in Firefox for AndroidModerate
CVE-2025-8042Sandboxed iframe could start downloadsModerate
CVE-2025-8029javascript: URLs executed on object and embed tagsModerate
CVE-2025-8036DNS rebinding circumvents CORSModerate
CVE-2025-8037Nameless cookies shadow secure cookiesModerate
CVE-2025-8030Potential user-assisted code execution in “Copy as cURL” commandModerate
CVE-2025-8043Incorrect URL truncationModerate
CVE-2025-8031Incorrect URL stripping in CSP reportsModerate
CVE-2025-8032XSLT documents could bypass CSPModerate
CVE-2025-8038CSP frame-src was not correctly enforced for pathsLow
CVE-2025-8039Search terms persisted in URL barLow
CVE-2025-8033Incorrect JavaScript state machine for generatorsLow

Android Fixes

Firefox for Android received specific attention with fixes for CVE-2025-8041 and CVE-2025-8042. 

The first addressed incorrect URL truncation in the address bar, where URLs were shortened from the end rather than prioritizing the origin display. 

The second vulnerability allowed sandboxed iframes without the allow-downloads attribute to initiate downloads, breaking the intended security sandbox.

The update also resolves cookie shadowing issues through CVE-2025-8037, where nameless cookies with equal signs could shadow secure cookies even when set over unencrypted HTTP connections. 

Mozilla strongly recommends all Firefox users update immediately to version 141 to protect against these vulnerabilities, which range from high-impact memory corruption issues to moderate privacy and security bypasses.

Boost detection, reduce alert fatigue, accelerate response; all with an interactive sandbox built for security teams -> Try ANY.RUN Now 

Kaaviya

Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago