CVE-2025-13020: Use-after-free in the WebRTC: Audio/Video component
Use-after-free in the WebRTC: Audio/Video component. This vulnerability affects Firefox < 145 and Firefox ESR < 140.5.
Other sources
Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
— MITRE
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-13020?
CVE-2025-13020 is classified as a critical severity vulnerability in the WebRTC component of Firefox.
How do I fix CVE-2025-13020?
To fix CVE-2025-13020, update your Firefox or Firefox ESR to versions 145 and 140.5 or later.
What versions of Firefox are affected by CVE-2025-13020?
CVE-2025-13020 affects Firefox versions below 145 and Firefox ESR versions below 140.5.
What component is impacted by CVE-2025-13020?
CVE-2025-13020 impacts the Audio/Video component of WebRTC in Firefox.
Is there a workaround for CVE-2025-13020?
There are no specific workarounds for CVE-2025-13020; updating to the latest version is recommended.