Mozilla FireFox Security Updates – 09 January 2025

Mozilla has released an updated Firefox version 134, Firefox ESR versions 128.6, and 115.19 to fix multiple vulnerabilities.

The addressed vulnerabilities could allow the attacker to perform spoofing attacks, gain elevated privileges, bypass security restrictions or execute arbitrary code and gain access to the affected system.

Sample of the addressed vulnerabilities:

1. Mozilla Firefox Memory Safety Bugs Vulnerability (CVE-2025-0247):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access

2. Mozilla Firefox WebChannel APIs Vulnerability (CVE-2025-0237):

  • CVSS: 5.4
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privileges
Vulnerabilities
  • CVE-2025-0237
  • CVE-2025-0238
  • CVE-2025-0239
  • CVE-2025-0240
  • CVE-2025-0241
  • CVE-2025-0242
  • CVE-2025-0243
  • CVE-2025-0244
  • CVE-2025-0245
  • CVE-2025-0246
  • CVE-2025-0247
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Mozilla Firefox Security Advisory

References