Critical severity9.8NVD Advisory· Published Oct 14, 2025· Updated Apr 13, 2026
CVE-2025-11719
CVE-2025-11719
Description
Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability was fixed in Firefox 144 and Thunderbird 144.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.mozilla.org/security/advisories/mfsa2025-81/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2025-84/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingPermissions Required
News mentions
0No linked articles in our index yet.