CVE-2025-1012
A race during concurrent delazification could have led to a use-after-free. This vulnerability was fixed in Firefox 135,
A race during concurrent delazification could have led to a use-after-free. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
HIGH · CVSS 7.5
EPSS 0.00427
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules1
YARA rules0