A critical vulnerability, tracked as CVE-2025-13016, was discovered in the WebAssembly engine's JavaScript component of Mozilla Firefox and Thunderbird, exposing over 180 million users to the risk of arbitrary code execution. The flaw, introduced in April 2025, results from incorrect boundary conditions in pointer arithmetic within the garbage collection process, leading to a stack buffer overflow. Attackers can exploit this vulnerability by luring users to malicious websites or sending crafted email content, potentially gaining complete control over the affected browser or mail client process. The vulnerability affects Firefox versions below 145 and Thunderbird versions prior to 145, including their respective ESR releases.
Mozilla responded promptly by releasing security patches in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird ESR 140.5. Security experts and vendors have emphasized the importance of immediate updates to mitigate the risk, as the flaw remained undetected for six months and could have compromised sensitive user data. Organizations and individuals are strongly advised to deploy the latest updates to ensure protection against potential exploitation of this high-severity vulnerability.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Security media publicly disclosed details of CVE-2025-13016, describing the arbitrary code execution risk from malicious webpages and the potential exposure of millions of Firefox users. Reports noted the bug had gone undetected for roughly six months before disclosure.
Mozilla released patched versions addressing CVE-2025-13016, including Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird ESR 140.5. Users and defenders were urged to update promptly to reduce exploitation risk.
AI security firm AISLE reportedly discovered CVE-2025-13016, a high-severity stack buffer overflow in Mozilla's WebAssembly engine that could enable arbitrary code execution. The issue affected Firefox and, according to reporting, Thunderbird as well when triggered through malicious content and user interaction.
The flaw later tracked as CVE-2025-13016 was reportedly introduced into Firefox in April 2025 in template-heavy WebAssembly garbage-collection code. The bug involved incorrect boundary checks and faulty pointer arithmetic that could lead to a stack buffer overflow.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.