CVE-2025-1011Active Exploitation(mozilla / firefox)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch mozilla firefox systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox
  • thunderbird

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Peaked 1d ago at 1 mentions (2026-02-25); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
firefoxthunderbird

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-25: 1Mentions · 2026-10-01: 1Active Exploitation · 2026-02-25: 1Patch / Workaround · 2026-02-25: 102-2510-01
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
Full discourse2 posts
  • DFIR Lab@DFIR_Lab

    🚨 HIGH: CVE-2025-1011 (CVSS 8.8) WebAssembly bug in Firefox/Thunderbird enables potential code execution via crash exploitation. Affected: Firefox <135, ESR <128.7, Thunderbird <128.7/135 Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/1lTk0ZcYop

    0000050
    144 followersView on X
  • PurpleOps@PurpleOps_io
    Active Exploitation

    📢 𝐍𝐞𝐰 𝐂𝐕𝐄 𝐚𝐧𝐚𝐥𝐲𝐬𝐢𝐬 𝐣𝐮𝐬𝐭 𝐝𝐫𝐨𝐩𝐩𝐞𝐝! Active exploitation of CVE-2025-1011 in FortiSIEM demands urgent patching; discover how to detect, defend, and minimize breach risk now before impact. 📖 Check the detailed report → https://www.purple-ops.io/cybersecurity-threat-intelligence-blog/cve-2025-1011-fortisiem-exploit-analysis/ Stay safe, and let us know your thoughts!

    Post summary

    The post announces that CVE-2025-1011 is actively exploited in FortiSIEM and urges immediate patching, with a link to a detailed analysis.

    0000043
    65 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox---
Appmozillafirefox---
Appmozillathunderbird---
Appmozillathunderbird---

Explore more