CVE-2025-14326: Use-after-free in the Audio/Video: GMP component
Published Dec 9, 2025
·Updated
Use-after-free in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 146 and Thunderbird 146.
Affected Software
5 affected componentsFixes available
Mozilla Firefox<146
Mozilla Firefox<146
146
Mozilla Thunderbird<146
146
Mozilla Firefox<146.0
Mozilla Thunderbird<146.0
Event History
Dec 9, 2025
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
Updated
via Mozilla·12:00 AM
Affected Software
CVE Published
via MITRE·01:38 PM
Data Sourced
via MITRE·01:38 PM
Description
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-14326?
CVE-2025-14326 has a high severity rating due to the potential for exploitation via a use-after-free condition.
2
How do I fix CVE-2025-14326?
To fix CVE-2025-14326, update to Mozilla Firefox version 146 or later.
3
Which versions of Firefox are affected by CVE-2025-14326?
CVE-2025-14326 affects all versions of Firefox prior to version 146.
4
What types of attacks can exploit CVE-2025-14326?
CVE-2025-14326 can potentially be exploited through crafted media content or web pages that trigger use-after-free vulnerabilities.
5
Is there a workaround for CVE-2025-14326 if I cannot update Firefox?
There are no specific workarounds for CVE-2025-14326, and the best mitigation is to upgrade to a patched version of Firefox.