Starting in Firefox 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability affects Firefox < 144 and Thunderbird < 144.
2025-10-14T13:15:38.287
2025-10-15T18:18:09.433
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mozilla | firefox | < 144.0 | Yes |
| Application | mozilla | thunderbird | < 144.0 | Yes |
| Operating System | microsoft | windows | - | No |