JIT Miscompilation in Firefox and Firefox ESR by Mozilla
CVE-2025-14325
7.3HIGH
Key Information:
- Vendor
Mozilla
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2025-14325?
A vulnerability in the Just-In-Time (JIT) compilation component of Firefox's JavaScript Engine has been identified. This issue affects versions of Firefox prior to 146 and Firefox ESR prior to 140.6, potentially leading to unexpected behavior or exploitation through malicious scripts. Users are recommended to update their browsers to the latest versions to ensure security and functionality.
Affected Version(s)
Firefox < 146
Firefox ESR < 140.6
Thunderbird < 146
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
zx