CVE-2025-14323
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-12-09

Last updated on: 2026-04-13

Assigner: Mozilla Corporation

Description
Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-09
Last Modified
2026-04-13
Generated
2026-05-07
AI Q&A
2025-12-09
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
mozilla firefox *
mozilla firefox_esr *
mozilla thunderbird to 140.6.0 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a privilege escalation issue in the DOM Notifications component of Firefox browsers. It affects versions of Firefox prior to 146 and Firefox ESR versions prior to 115.31 and 140.6. Privilege escalation means that an attacker could potentially gain higher-level permissions than intended within the browser environment.


How can this vulnerability impact me? :

This vulnerability can allow an attacker to escalate their privileges within the Firefox browser, potentially leading to unauthorized access to sensitive information, modification of data, or disruption of services. The CVSS score indicates a high impact on confidentiality, integrity, and availability.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, update Firefox to version 146 or later, or Firefox ESR to version 115.31 or later (for ESR 115) or 140.6 or later (for ESR 140). These updates include fixes for the privilege escalation vulnerability in the DOM Notifications component. [3]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart