CVE-2025-13014
8.8Mozilla · Firefox, Thunderbird
A use-after-free vulnerability exists in the Audio/Video component of Mozilla Firefox and Thunderbird, potentially allowing for remote code execution via malicious web content.
Executive summary
A high-severity use-after-free vulnerability in Mozilla Firefox and Thunderbird could allow an unauthenticated attacker to execute arbitrary code on a victim system.
Vulnerability
This is a use-after-free memory corruption flaw within the Audio/Video processing engine. The vulnerability is triggered by an unauthenticated attacker, typically through a user navigating to a specially crafted website or opening malicious content.
Business impact
The vulnerability carries a CVSS score of 8.8, reflecting its potential for total compromise of the host system. Successful exploitation allows an attacker to achieve remote code execution, which could lead to unauthorized data access, the installation of malware, or complete system takeover. This poses a significant risk to organizational endpoints and the integrity of sensitive information processed within the browser or mail client.
Remediation
Immediate Action: Update Mozilla Firefox and Thunderbird to the latest versions (145 or higher, or the specified ESR releases) immediately to apply the vendor-provided security patches.
Proactive Monitoring: Monitor endpoint security logs for unusual crash events or unexpected child process spawning associated with browser or mail client activity, which may indicate exploitation attempts.
Compensating Controls: Ensure that security software, such as endpoint detection and response (EDR) tools, is active to detect and block malicious process execution triggered by browser-based memory exploits.
Exploitation status
Public Exploit Available: No (exploit_available: false)
More Mozilla CVEs
Sources
Originally found and disclosed by Andrew Osmond, per the CVE Program record.