Mozilla sent Firefox Version 138.0.4 to the Release Channel with two critical security updates.
Fixed
#CVE-2025-4920: Out-of-bounds access when resolving Promise objects
#CVE-2025-4921: Out-of-bounds access when optimizing linear sums
Update: To get the update now, select "Help" from the Firefox menu and pick "About Firefox". Mac users need to select "About Firefox" from the Firefox menu. If you do not use the English language version, Fully Localized Versions are available for download.
Release Notes
Fixed
#CVE-2025-4920: Out-of-bounds access when resolving Promise objects
#CVE-2025-4921: Out-of-bounds access when optimizing linear sums
Update: To get the update now, select "Help" from the Firefox menu and pick "About Firefox". Mac users need to select "About Firefox" from the Firefox menu. If you do not use the English language version, Fully Localized Versions are available for download.
Release Notes