CVE-2025-8027
MEDIUMCVSS 6.5/10EPSS 0.35%
Last modified
CVE-2025-8027 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 115.26.0 |
| Mozilla | Firefox | < 141.0 |
| Mozilla | Firefox | >= 128.0, < 128.13.0 |
| Mozilla | Firefox | >= 140.0, < 140.1.0 |
| Mozilla | Thunderbird | < 128.13.0 |
| Mozilla | Thunderbird | < 141.0 |
| Mozilla | Thunderbird | >= 140.0, < 140.1.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1968423Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2025-56/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-57/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-58/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-59/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-61/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-62/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-63/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-8027?
On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.
How severe is CVE-2025-8027?
CVE-2025-8027 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 0.35% probability of exploitation in the next 30 days.
How do I fix CVE-2025-8027?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-8019A vulnerability was found in Shenzhen Libituo Technology LBT…8.8
- CVE-2025-8020All versions of the package private-ip are vulnerable to Ser…8.2
- CVE-2025-8021All versions of the package files-bucket-server are vulnerab…7.7
- CVE-2025-8022Rejected reason: Bun Shell does not invoke /bin/sh, or any o…
- CVE-2025-8023Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11…4.9
- CVE-2025-8025Missing Authentication for Critical Function, Improper Acces…9.8
- CVE-2025-8028On arm64, a WASM `br_table` instruction with a lot of entrie…9.8
- CVE-2025-8029Thunderbird executed `javascript:` URLs when used in `object…8.1
- CVE-2025-8030Insufficient escaping in the “Copy as cURL” feature could po…8.1
- CVE-2025-8031The `username:password` part was not correctly stripped from…9.8
- CVE-2025-8032XSLT document loading did not correctly propagate the source…8.1
- CVE-2025-8033The JavaScript engine did not handle closed generators corre…6.5
Are you affected by CVE-2025-8027?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
