CVE-2025-13014: Use-after-free in the Audio/Video component
Use-after-free in the Audio/Video component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, and Firefox ESR < 115.30.
Other sources
Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5.
— MITRE
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-13014?
CVE-2025-13014 is classified as a critical use-after-free vulnerability affecting certain versions of Mozilla Firefox and Firefox ESR.
How do I fix CVE-2025-13014?
To fix CVE-2025-13014, update your Firefox or Firefox ESR to the latest version that is not affected by this vulnerability.
Which versions are affected by CVE-2025-13014?
CVE-2025-13014 affects Firefox versions prior to 145 and Firefox ESR versions prior to 140.5 and 115.30.
What can exploit CVE-2025-13014?
CVE-2025-13014 can be exploited through specially crafted media content that may lead to execution of arbitrary code.
Is there a known workaround for CVE-2025-13014?
There are no known workarounds for CVE-2025-13014; the recommended action is to update to the patched versions.