CVE-2025-14333: Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146
Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 146 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 146 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.6 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 146 - Upgrade
Upgrade
Thunderbird ESRto a version that resolves this vulnerability.Fixed in 140.6
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-14333?
CVE-2025-14333 has been identified with a high severity level due to potential exploitation for arbitrary code execution.
How do I fix CVE-2025-14333?
To fix CVE-2025-14333, update Mozilla Firefox and Thunderbird to versions 140.6 or later.
Which versions are affected by CVE-2025-14333?
CVE-2025-14333 affects Firefox ESR versions up to 140.5, Thunderbird ESR versions up to 140.5, and standard Firefox and Thunderbird versions up to 145.
What type of vulnerability is CVE-2025-14333?
CVE-2025-14333 is a memory safety bug that can lead to memory corruption.
Is there a known exploit for CVE-2025-14333?
While there are no confirmed exploits publicly available for CVE-2025-14333, the nature of the bug could allow for arbitrary code execution if successfully exploited.