logo

CVE-2025-4919: Corruption via Math Space in Mozilla Firefox

ID: 5237aa18-84e1-5066-b938-7752f466f198

STIX ID: report--5237aa18-84e1-5066-b938-7752f466f198

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
75/100

Date Published: 2025-07-15

Date Updated: 2026-05-01

Author: Hossein Lotfi

...
...

**Executive summary:** The report details a high-quality bounds-check elimination bug in a JavaScript engine's JIT/RangeAnalysis that, when combined with large typed-array allocations, enables controlled out-of-bounds reads and writes. The author describes gaining addrOf and fakeObj primitives by corrupting Map pointers, building fake objects and overlapping ArrayBuffers to achieve arbitrary read/write, and using WASM-embedded shellcode to obtain code execution; a public demo and Pwn2Own disclosure are referenced.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.