iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Mozilla fixed two critical Firefox vulnerabilities, CVE-2025-4918 and CVE-2025-4919, in Firefox 138.0.4. Organizations should identify affected installations, deploy a currently supported Firefox release, and verify that updates reached managed endpoints. Firefox 138.0.4 is the specific fix named in Mozilla’s May 17, 2025 advisory; check Mozilla’s release index for the currently supported version before deployment.
What are the recent Firefox zero-days?
Mozilla’s MFSA 2025-36, announced May 17, 2025, covers two critical vulnerabilities in Firefox. The advisory identifies both as out-of-bounds access flaws involving JavaScript objects.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages | $22.99 | Buy on Amazon |
| 2 |
|
Firefox For Dummies | $44.22 | Buy on Amazon |
| 3 |
|
BookFactory Security Incident Report Log Book, Wire-O, 100 Pages | $9.99 | Buy on Amazon |
| 4 |
|
Firefox and Thunderbird Garage (The Garage Series) | $300.00 | Buy on Amazon |
- CVE-2025-4918: An attacker could perform an out-of-bounds read or write on a JavaScript
Promiseobject. - CVE-2025-4919: An attacker could perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes during linear-sum optimization.
Mozilla rated both vulnerabilities critical. The advisory establishes severity and the fixed release, but does not quantify exploitation, affected organizations, or patch-compliance rates. Treat these issues as urgent browser vulnerabilities without assuming a measured exploitation rate.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Which Firefox version fixes CVE-2025-4918 and CVE-2025-4919?
Mozilla names Firefox 138.0.4 as the version that fixes both vulnerabilities in MFSA 2025-36. That is the specific build associated with this advisory, not a recommendation to install an old release today. Deploy a currently supported Firefox release that includes the fixes, and consult Mozilla’s security advisory index for later releases and channel-specific information.
#1 Best Overall
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
Do not assume a standard Firefox version number applies to every deployment. Inventory standard Firefox, Firefox ESR, and any managed browser channels separately, then confirm that the chosen supported release for each channel contains the relevant fixes.
Do organizations need to patch Firefox immediately?
Organizations should prioritize remediation across their Firefox endpoint fleet rather than wait for routine patching. Mozilla classifies both issues as critical, and browsers regularly process web content from outside an organization’s control. That makes unpatched browser installations an exposure to address promptly.
Rank #2
CISA’s Known Exploited Vulnerabilities (KEV) catalog is an authoritative catalog of vulnerabilities exploited in the wild and is intended to inform vulnerability-management prioritization. Its referenced Firefox entry is for the distinct vulnerability CVE-2024-9680, a use-after-free in animation timelines that can enable code execution in the content process; it is not evidence that CVE-2025-4918 or CVE-2025-4919 is listed or being exploited. Use CISA’s KEV catalog alongside your own exposure and threat data when setting remediation deadlines.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsQuick Recap
Rank #3
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- This BookFactory log book is for security guards in any sector or business. You can report location, circumstances and report number.
- There are spaces to log the individual's names address, description and other identifying information. There are also spaces to note others involved, notes, and vehicle information if one was involved
- Wire-O, 100 Pages, Dimensions 3.5" x 5.25"
- Reorder SKU: LOG-100-M3CW-PP(Security-Report)
How to check and patch a Firefox fleet
- Inventory installations. Identify Firefox endpoints, including standard, ESR, and enterprise-managed channels. Include devices that may be offline or used infrequently so they are not missed.
- Choose the supported fixed release. Firefox 138.0.4 is the build named in MFSA 2025-36. For deployment now, verify the current supported release and applicable channel details in Mozilla’s advisory index.
- Deploy the update. Allow browser auto-update where that is your organization’s managed approach, or use centralized enterprise deployment. Ensure update policies do not leave users on a vulnerable version.
- Verify completion. Check installed versions on representative endpoints and compare fleet inventory with the expected release. Validate that auto-update or the enterprise deployment process completed successfully; do not treat an update policy being enabled as proof that every endpoint updated.
- Set remediation deadlines. Use CISA KEV prioritization where applicable, internal exposure data, and organizational risk criteria. The catalog’s cited Firefox entry concerns CVE-2024-9680, so do not conflate it with these two 2025 CVEs.
- Review for suspicious activity. Check browser telemetry, endpoint alerts, and threat-hunting data for relevant suspicious activity involving vulnerable clients. This is prudent defensive practice; the cited sources do not provide a measured exploitation rate for CVE-2025-4918 or CVE-2025-4919.
Choosing an update and verification approach
| Decision area | What to do |
|---|---|
| Release channel | Inventory standard Firefox and ESR separately; verify the supported fixed release applicable to each channel using Mozilla’s advisory index. |
| Deployment method | Use automatic updates or centralized enterprise management according to your environment, then confirm successful installation on endpoints. |
| Verification | Combine version inventory with endpoint telemetry; a deployment command or policy alone does not demonstrate fleet-wide completion. |
| Urgency | Prioritize according to Mozilla’s critical severity, CISA KEV guidance where applicable, and your internal exposure data. The cited KEV Firefox entry is for CVE-2024-9680, not these CVEs. |
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

