CVE-2025-13020
8.8Mozilla · Firefox, Thunderbird
A use-after-free vulnerability exists in the WebRTC Audio/Video component of Mozilla Firefox and Thunderbird, which could lead to arbitrary code execution.
Executive summary
A critical use-after-free vulnerability in Mozilla Firefox and Thunderbird allows unauthenticated remote attackers to potentially execute arbitrary code.
Vulnerability
This is a use-after-free memory corruption flaw located in the WebRTC Audio/Video component. The vulnerability can be triggered by an unauthenticated remote attacker through a specially crafted web page or malicious content.
Business impact
The CVSS score of 8.8 reflects the high severity of this flaw, as it permits potential remote code execution on the user's system. Successful exploitation could lead to full system compromise, data theft, or the installation of persistent malware, resulting in significant operational and reputational risk to the organization.
Remediation
Immediate Action: Update all installations of Mozilla Firefox and Thunderbird to version 145 or 140.5 ESR respectively to incorporate the necessary security patches.
Proactive Monitoring: Monitor endpoint logs for unusual browser activity or unexpected process crashes that may indicate an attempt to trigger memory corruption.
Compensating Controls: Ensure that endpoint protection software is active and configured to detect malicious web traffic or unauthorized process execution.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high severity of this vulnerability and its potential for remote code execution, organizations must prioritize the deployment of the Mozilla security updates. Administrators should treat this update as a high-priority task to ensure all browser instances are protected against potential exploitation.
More Mozilla CVEs
Sources
Originally found and disclosed by Andreas Pehrson, per the CVE Program record.