CVE-2025-14327: Spoofing issue in the Downloads Panel component
Published Dec 9, 2025
·Updated
Spoofing issue in the Downloads Panel component. This vulnerability affects Firefox < 146.
Other sources
Spoofing issue in the Downloads Panel component. This vulnerability was fixed in Firefox 146, Thunderbird 146, Firefox ESR 140.7, and Thunderbird 140.7.
— MITRE
Affected Software
7 affected componentsFixes available
Mozilla Firefox<146
Mozilla Firefox<146
146
Mozilla Thunderbird<146
146
Mozilla Firefox ESR<140.7
140.7
Mozilla Firefox<146.0
Mozilla Thunderbird<146.0
Mozilla Thunderbird<140.7
140.7
Event History
Dec 9, 2025
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
Updated
via Mozilla·12:00 AM
Affected Software
CVE Published
via MITRE·01:38 PM
Data Sourced
via MITRE·01:38 PM
Description
Data Sourced
via Red Hat·02:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeaknessAffected Software
Jan 13, 2026
Updated
via Mozilla·12:00 AM
Affected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-14321
- CVE-2025-14322
- CVE-2025-14323
- CVE-2025-14324
- CVE-2025-14325
- CVE-2025-14326
- CVE-2025-14327
- CVE-2025-14328
- CVE-2025-14329
- CVE-2025-14330
- CVE-2025-14331
- CVE-2025-14332
- CVE-2025-14333
- CVE-2026-0877
- CVE-2026-0878
- CVE-2026-0879
- CVE-2026-0880
- CVE-2026-0882
- CVE-2026-0883
- CVE-2026-0884
- CVE-2026-0885
- CVE-2026-0886
- CVE-2026-0887
- CVE-2026-0890
- CVE-2026-0891
Frequently Asked Questions
1
What is the severity of CVE-2025-14327?
CVE-2025-14327 is categorized as a spoofing vulnerability.
2
How do I fix CVE-2025-14327?
To fix CVE-2025-14327, update your Firefox browser to version 146 or later.
3
What versions of Firefox are affected by CVE-2025-14327?
CVE-2025-14327 affects all versions of Firefox prior to version 146.
4
What is the impact of CVE-2025-14327?
The impact of CVE-2025-14327 is that it may allow attackers to spoof content in the Downloads Panel.
5
Where can I find more information about CVE-2025-14327?
More information about CVE-2025-14327 can be found on the Mozilla security advisories page.