What the vulnerability does

01Description

When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

Key dates

02Disclosure timeline

January 7, 2025 CVE published
April 13, 2026 Record updated