CVE-2025-8028 Information

Description

On arm64 a WASM br_table instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability affects Firefox < 141 Firefox ESR < 115.26 Firefox ESR < 128.13 Firefox ESR < 140.1 Thunderbird < 141 Thunderbird < 128.13 and Thunderbird < 140.1.

Reference

https://bugzilla.mozilla.org/show_bug.cgi?id=1971581 https://www.mozilla.org/security/advisories/mfsa2025-56/ https://www.mozilla.org/security/advisories/mfsa2025-57/ https://www.mozilla.org/security/advisories/mfsa2025-58/ https://www.mozilla.org/security/advisories/mfsa2025-59/ https://www.mozilla.org/security/advisories/mfsa2025-61/ https://www.mozilla.org/security/advisories/mfsa2025-62/ https://www.mozilla.org/security/advisories/mfsa2025-63/

CNNVD-202507-2923 (Published: 2025-07-22)

Share on: