Memory safety bugs present in Firefox 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 146.0.1.
History

Thu, 18 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 14:30:00 +0000

Type Values Removed Values Added
Description Memory safety bugs present in Firefox 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 146.0.1.
Title Memory safety bugs fixed in Firefox 146.0.1
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2025-12-18T15:39:55.092Z

Reserved: 2025-12-18T00:22:11.950Z

Link: CVE-2025-14861

cve-icon Vulnrichment

Updated: 2025-12-18T15:39:20.216Z

cve-icon NVD

Status : Received

Published: 2025-12-18T15:15:53.157

Modified: 2025-12-18T16:15:52.647

Link: CVE-2025-14861

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.