Mozilla has released Firefox version 138, addressing several serious security flaws and introducing long-awaited features, such as improved profile management.
See also: Chrome 136 fixes 20-year-old bug in browser history

Security researchers have identified multiple critical vulnerabilities that could allow attackers to escalate privileges or bypass security mechanisms. This led to the release of an important security update on April 29, 2025. The Mozilla Foundation Security Advisory describes four high-risk flaws that were fixed with Firefox version 138. The most concerning issues include an elevation of privilege flaw, a memory corruption , and a process isolation bypass.
CVE -2025-2817, discovered by security researcher Dong-uk Kim (@justlikebono), exposed a serious vulnerability in Firefox's update process. The flaw allowed middle-level user processes to interfere with updates running with SYSTEM privilegesby exploiting file lock handling.
See also: Chrome 135 and Firefox 137 fix high-severity vulnerabilities
For macOS users, CVE-2025-4082 created a memory corruption issue in WebGL shader features, which could cause an out-of-bounds memory read. When combined with other vulnerabilities, this flaw could be exploited to escalate privileges on affected systems.

Another significant vulnerability, CVE-2025-4083, reported by Nika Layzell, involved bypassing process isolation via URI links in cross-origin frames. The issue stemmed from incorrect handling of URIs of the javascript:, potentially allowing content to run in the top-level document's process instead of the intended frame — which could lead to a sandbox exit.
Mozilla also fixed memory-related security flaws, codenamed CVE-2025-4092, which affected both Firefox 137 and Thunderbird 137.These flaws showed signs of memory corruption and could potentially be exploited to execute arbitrary code.
See also: Chrome 134 and Firefox 136 fix critical vulnerabilities
Based on the above, it is clear that Mozilla is strongly focused on strengthening the security of Firefox, especially in environments like macOS, where specific flaws — such as memory corruption in WebGL or isolation bypass via javascript: URIs — can lead to serious risks, such as malicious code execution or sandbox escape. This shows how important it is to continuously monitor and fix vulnerabilities in the browser, as it is an application that is a daily target of attacks, mainly due to its connection to the internet and users' personal data.
Source: cybersecuritynews
