CVE-2025-49710
NixOS Analyse et atténuation des vulnérabilités

Aperçu

CVE-2025-49710 is an integer overflow vulnerability in the OrderedHashTable component of Mozilla Firefox's JavaScript engine. Discovered and reported by external researcher Shaheen Fazim, it was publicly disclosed on June 10, 2025, alongside the release of Firefox 139.0.4. The vulnerability affects all Firefox versions prior to 139.0.4; Firefox ESR 115 and ESR 128 are unaffected. It carries a CVSS v3.1 base score of 9.8 (Critical) (Mozilla Advisory, Feedly).

Détails techniques

The root cause is an integer overflow (CWE-190) in OrderedHashTableImpl::rehash(), triggered when the JavaScript engine's Map or Set objects grow to an extremely large number of entries. The code used a size_t value for the desired allocation size but passed it to AllocNurseryOrMallocBuffer, which accepts only a uint32_t argument — causing a truncation/overflow when the entry count exceeds approximately 170 million, far beyond what Chrome (16 million) or JavaScriptCore (25 million) allow. This results in an undersized buffer allocation followed by an out-of-bounds memcpy write (SEGV WRITE in __memcpy_avx_unaligned_erms), as confirmed by AddressSanitizer output in the bug report. The fix restricts the maximum number of Map/Set entries to prevent the overflow condition (Mozilla Bugzilla, Mozilla Advisory).

Impact

Successful exploitation could lead to memory corruption, enabling an attacker to potentially execute arbitrary code in the context of the browser process, compromise browser integrity, or cause application crashes. Because the vulnerability resides in the JavaScript engine, it could be triggered by a malicious web page visited by a user, affecting confidentiality, integrity, and availability of the browser and potentially the underlying system. The vulnerability is rated high impact by Mozilla and carries a critical CVSS score reflecting the potential for unauthenticated remote code execution (Mozilla Advisory, Feedly).

Exploitabilité

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). A PoC script (poc.js) was submitted by the reporter to Mozilla's bug tracker but is not publicly accessible. The EPSS score is approximately 0.043%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Mozilla's security team noted that constructing a reliable exploit would likely not be "super difficult" given the nature of the patch (Mozilla Bugzilla).

Étapes d’exploitation

  1. Craft a malicious web page: Create an HTML page containing JavaScript that instantiates a Map or Set object and populates it with an extremely large number of entries (approaching or exceeding ~170 million) to trigger the integer overflow in OrderedHashTableImpl::rehash().
  2. Trigger the overflow: As the Map/Set grows, the engine calls rehash(), which computes a size_t allocation size that overflows when cast to uint32_t, resulting in an undersized buffer being allocated.
  3. Cause out-of-bounds write: The subsequent memcpy into the undersized buffer writes beyond its bounds, corrupting adjacent heap memory.
  4. Achieve code execution (theoretical): With sufficient heap shaping and memory manipulation techniques, an attacker could potentially redirect execution flow to attacker-controlled code, though reliable exploitation would require additional effort beyond the basic crash (Mozilla Bugzilla).

Indicateurs de compromis

  • Process: Firefox process crashing or becoming unresponsive after visiting a web page; abnormal memory consumption by the Firefox process reaching multi-gigabyte levels.
  • Logs: Browser crash reports referencing OrderedHashTableImpl::rehash or __memcpy_avx_unaligned_erms in stack traces; AddressSanitizer output with SEGV WRITE signals (in debug builds).
  • Network: Unexpected outbound connections from the Firefox process following a page visit to an unknown or suspicious domain, which could indicate post-exploitation activity.

Atténuation et solutions de contournement

Mozilla has released Firefox 139.0.4, which resolves this vulnerability by restricting the maximum number of entries allowed in Map and Set objects, preventing the integer overflow condition. Firefox ESR 115 and ESR 128 are unaffected and do not require updates for this specific issue. Users should update Firefox to version 139.0.4 or later immediately, and enabling automatic browser updates is strongly recommended to ensure timely patching of future issues (Mozilla Advisory, Mozilla Bugzilla).

Réactions de la communauté

The CIS issued an advisory noting that multiple vulnerabilities in Firefox 139.0.4, including CVE-2025-49710, could allow for arbitrary code execution (CIS Advisory). SecurityWeek covered the release alongside Chrome updates, framing both as high-severity memory bug fixes. Security news outlets including CyberSecurityNews and SecurityOnline.info highlighted the critical CVSS score and potential for remote code execution. Community reaction was generally focused on the urgency of updating, with the vulnerability receiving a security bounty from Mozilla (Mozilla Bugzilla).

Ressources additionnelles

État de correction de la distribution Linux

Disponibilité des correctifs sur les principales distributions Linux et leurs versions.

Debian

Fixe

sid

firefox: 139.0.4-1

Fixe

Ubuntu

Inconnu

bionic (esm-apps)

mozjs38

Inconnu

devel

firefox

Non affecté

jammy

firefox

Non affecté

noble

firefox

Non affecté

questing

firefox

Non affecté

resolute

firefox

Non affecté

SourceCe rapport a été généré à l’aide de l’IA

Apparenté NixOS Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-78662HIGH7.5
  • Docker logoDocker
  • argo-workflows-fips-4.1
NonOuiSep 02, 2026
CVE-2026-56855HIGH7.5
  • Docker logoDocker
  • grafana-13.2
NonOuiSep 02, 2026
CVE-2026-84642HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NonOuiSep 01, 2026
CVE-2026-84641HIGH7.5
  • NixOS logoNixOS
  • thunderbird
NonOuiSep 01, 2026
CVE-2026-32773MEDIUM6.1
  • NixOS logoNixOS
  • spark
NonOuiSep 02, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités