---
id: CVE-2025-8028
title: >-
  On arm64, a WASM `br_table` instruction with a lot of entries could lead to
  the label being too far from the instruction causing truncation and incorrect
  computation of the branch address
summary: >-
  On arm64, a WASM `br_table` instruction with a lot of entries could lead to
  the label being too far from the instruction causing truncation and incorrect
  computation of the branch address. This vulnerability was fixed in Firefox
  141, Fir…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-1332
vendor: mozilla
product: firefox
affected:
  - firefox < 115.26.0
  - firefox < 141.0
  - 'firefox >= 128.0, < 128.13.0'
  - 'firefox >= 140.0, < 140.1.0'
  - thunderbird < 128.13.0
  - thunderbird < 141.0
  - 'thunderbird >= 140.0, < 140.1.0'
patched:
  - firefox 140.1.0
  - thunderbird 140.1.0
published: '2025-07-22'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T18:10:00.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-8028'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1971581'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-56/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-57/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-58/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-59/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-61/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-62/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-63/'
    label: security@mozilla.org
  - url: 'https://lists.debian.org/debian-lts-announce/2025/07/msg00016.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00509
epssPercentile: 0.41193
ingestedAt: '2026-09-30T18:17:24.447Z'
---

## Overview

On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.

## Affected

- `firefox < 115.26.0`
- `firefox < 141.0`
- `firefox >= 128.0, < 128.13.0`
- `firefox >= 140.0, < 140.1.0`
- `thunderbird < 128.13.0`
- `thunderbird < 141.0`
- `thunderbird >= 140.0, < 140.1.0`

## Remediation

Upgrade past the affected range:

- `firefox 140.1.0`
- `thunderbird 140.1.0`
