Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

zetlyn/cve-nvd vulnerability cve CVE-2025-0240 cpe cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* cpe cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* cpe cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* known 2025-01-07

https://nvd.nist.gov/vuln/detail/CVE-2025-0240

Properties

cvss4
receipt
Source
NVD
Its words
4.0
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.6",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "134",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.6",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "134",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "AEBB7F43-496D-4A67-8E9E-EEE29913B6DE",
                "versionEndExcluding": "128.6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "4FDCA935-A68D-404E-A749-CA3845C709F0",
                "versionEndExcluding": "134.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C92D62DE-A681-4B9D-9640-D12D04392A1B",
                "versionEndExcluding": "128.6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A633E231-80F8-4A92-BA69-B9BE5BE45D00",
                "versionEndExcluding": "134.0",
                "versionStartIncluding": "129.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6."
      },
      {
        "lang": "es",
        "value": "Analizar un módulo de JavaScript como JSON podría, en algunas circunstancias, provocar un acceso entre compartimentos, lo que puede dar lugar a use-after-free. Esta vulnerabilidad afecta a Firefox < 134 y Firefox ESR < 128.6."
      }
    ],
    "id": "CVE-2025-0240",
    "lastModified": "2026-09-30T19:10:01.007",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 4.0,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.5,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-0240",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-01-08T16:36:55.988099Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-01-07T16:15:38.663",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Issue Tracking",
          "Permissions Required"
        ],
        "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1929623"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-01/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-02/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-04/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-05/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00004.html"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-416"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
productFirefox
receipt
Source
NVD
Its words
Firefox
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.6",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "134",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.6",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "134",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "AEBB7F43-496D-4A67-8E9E-EEE29913B6DE",
                "versionEndExcluding": "128.6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "4FDCA935-A68D-404E-A749-CA3845C709F0",
                "versionEndExcluding": "134.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C92D62DE-A681-4B9D-9640-D12D04392A1B",
                "versionEndExcluding": "128.6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A633E231-80F8-4A92-BA69-B9BE5BE45D00",
                "versionEndExcluding": "134.0",
                "versionStartIncluding": "129.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6."
      },
      {
        "lang": "es",
        "value": "Analizar un módulo de JavaScript como JSON podría, en algunas circunstancias, provocar un acceso entre compartimentos, lo que puede dar lugar a use-after-free. Esta vulnerabilidad afecta a Firefox < 134 y Firefox ESR < 128.6."
      }
    ],
    "id": "CVE-2025-0240",
    "lastModified": "2026-09-30T19:10:01.007",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 4.0,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.5,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-0240",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-01-08T16:36:55.988099Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-01-07T16:15:38.663",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Issue Tracking",
          "Permissions Required"
        ],
        "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1929623"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-01/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-02/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-04/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-05/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00004.html"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-416"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
statusModified
receipt
Source
NVD
Its words
Modified
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.6",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "134",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.6",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "134",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "AEBB7F43-496D-4A67-8E9E-EEE29913B6DE",
                "versionEndExcluding": "128.6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "4FDCA935-A68D-404E-A749-CA3845C709F0",
                "versionEndExcluding": "134.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C92D62DE-A681-4B9D-9640-D12D04392A1B",
                "versionEndExcluding": "128.6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A633E231-80F8-4A92-BA69-B9BE5BE45D00",
                "versionEndExcluding": "134.0",
                "versionStartIncluding": "129.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6."
      },
      {
        "lang": "es",
        "value": "Analizar un módulo de JavaScript como JSON podría, en algunas circunstancias, provocar un acceso entre compartimentos, lo que puede dar lugar a use-after-free. Esta vulnerabilidad afecta a Firefox < 134 y Firefox ESR < 128.6."
      }
    ],
    "id": "CVE-2025-0240",
    "lastModified": "2026-09-30T19:10:01.007",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 4.0,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.5,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-0240",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-01-08T16:36:55.988099Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-01-07T16:15:38.663",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Issue Tracking",
          "Permissions Required"
        ],
        "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1929623"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-01/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-02/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-04/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-05/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00004.html"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-416"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
vendorMozilla
receipt
Source
NVD
Its words
Mozilla
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Firefox",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.6",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "134",
                "versionType": "rpm"
              }
            ]
          },
          {
            "product": "Thunderbird",
            "vendor": "Mozilla",
            "versions": [
              {
                "lessThanOrEqual": "128.*",
                "status": "unaffected",
                "version": "128.6",
                "versionType": "rpm"
              },
              {
                "lessThanOrEqual": "*",
                "status": "unaffected",
                "version": "134",
                "versionType": "rpm"
              }
            ]
          }
        ],
        "source": "security@mozilla.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
                "matchCriteriaId": "AEBB7F43-496D-4A67-8E9E-EEE29913B6DE",
                "versionEndExcluding": "128.6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "4FDCA935-A68D-404E-A749-CA3845C709F0",
                "versionEndExcluding": "134.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C92D62DE-A681-4B9D-9640-D12D04392A1B",
                "versionEndExcluding": "128.6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A633E231-80F8-4A92-BA69-B9BE5BE45D00",
                "versionEndExcluding": "134.0",
                "versionStartIncluding": "129.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6."
      },
      {
        "lang": "es",
        "value": "Analizar un módulo de JavaScript como JSON podría, en algunas circunstancias, provocar un acceso entre compartimentos, lo que puede dar lugar a use-after-free. Esta vulnerabilidad afecta a Firefox < 134 y Firefox ESR < 128.6."
      }
    ],
    "id": "CVE-2025-0240",
    "lastModified": "2026-09-30T19:10:01.007",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 4.0,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.5,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-0240",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-01-08T16:36:55.988099Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-01-07T16:15:38.663",
    "references": [
      {
        "source": "security@mozilla.org",
        "tags": [
          "Issue Tracking",
          "Permissions Required"
        ],
        "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1929623"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-01/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-02/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-04/"
      },
      {
        "source": "security@mozilla.org",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://www.mozilla.org/security/advisories/mfsa2025-05/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00004.html"
      }
    ],
    "sourceIdentifier": "security@mozilla.org",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-416"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}

Text

Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6. Analizar un módulo de JavaScript como JSON podría, en algunas circunstancias, provocar un acceso entre compartimentos, lo que puede dar lugar a use-after-free. Esta vulnerabilidad afecta a Firefox < 134 y Firefox ESR < 128.6.