CVE-2025-14323

8.8

Mozilla · Firefox and Thunderbird

A privilege escalation vulnerability exists in the Notifications component of the DOM in Mozilla Firefox and Thunderbird, potentially allowing an attacker to gain elevated privileges.

Executive summary

A critical privilege escalation vulnerability in Mozilla Firefox and Thunderbird could allow an attacker to bypass security controls and gain unauthorized elevated access.

Vulnerability

The flaw resides in the DOM Notifications component, which fails to properly enforce privilege boundaries. Exploitation requires user interaction via a network-based vector, allowing an unauthenticated remote attacker to gain elevated privileges within the application context.

Business impact

Successful exploitation of this vulnerability can lead to a complete compromise of the affected client application, potentially resulting in unauthorized data access or the execution of arbitrary code within the user session. Given the CVSS score of 8.8, this vulnerability represents a significant risk to organizational endpoints, necessitating immediate attention to prevent potential system-wide security breaches.

Remediation

Immediate Action: Update Mozilla Firefox and Thunderbird to version 146 or higher, or the applicable Extended Support Release (ESR) versions 115.31 or 140.6, to apply the necessary security patches.

Proactive Monitoring: Monitor endpoint security logs for unusual process execution or attempts to access restricted system resources originating from the browser or email client.

Compensating Controls: While no direct virtual patch exists, enforcing strict browser security policies and limiting user permissions on local workstations can reduce the potential blast radius of an exploited client-side application.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations must prioritize the deployment of the provided security updates across all managed instances of Firefox and Thunderbird. Because this vulnerability allows for privilege escalation, delay in patching increases the risk of successful weaponization by threat actors who may target vulnerable browsers for initial access or lateral movement.

More Mozilla CVEs

Sources

Originally found and disclosed by tiebuchen, per the CVE Program record.