CVE-2025-14328
BaseFortify
Publication date: 2025-12-09
Last updated on: 2026-04-13
Assigner: Mozilla Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mozilla | firefox | * |
| mozilla | firefox_esr | * |
| mozilla | thunderbird | to 140.6.0 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a privilege escalation issue in the Netmonitor component of Firefox. It affects Firefox versions earlier than 146 and Firefox ESR versions earlier than 140.6. Privilege escalation means an attacker could gain higher access rights than intended.
How can this vulnerability impact me? :
This vulnerability can allow an attacker to escalate their privileges, potentially leading to full control over the affected system or application. This can result in unauthorized access, data compromise, or disruption of services.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, update Firefox to version 146 or later, and Firefox ESR to version 140.6 or later.