CVE-2025-14333
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-14333 is a memory safety vulnerability affecting Mozilla Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR. Specifically, it involves memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145, and Thunderbird 145, where some bugs showed evidence of memory corruption that could potentially be exploited to execute arbitrary code. The vulnerability was discovered by Maurice Dauer and the Mozilla Fuzzing Team and disclosed on December 9, 2025. It carries a CVSS v3.1 base score of 8.1 (High) and is rated Moderate severity by Mozilla (Mozilla Advisory mfsa2025-92, Mozilla Advisory mfsa2025-94).

Technical details

The vulnerability is classified under CWE-787 (Out-of-bounds Write) and CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), reflecting multiple memory safety bugs discovered through fuzzing. The bugs involve memory corruption in the browser engine components shared across Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145, and Thunderbird 145. Mozilla's advisory notes that while exploitation would require significant effort, the memory corruption evidence suggests arbitrary code execution is theoretically achievable. The underlying bug IDs referenced are 1966501 and 1997639 in Mozilla's Bugzilla (Mozilla Advisory mfsa2025-92, Mozilla Advisory mfsa2025-94).

Impact

Successful exploitation of CVE-2025-14333 could allow a remote attacker to execute arbitrary code on affected systems, compromising confidentiality, integrity, and availability. Given the network-based attack vector and the browser/email client context, exploitation could result in full compromise of the user's session, access to sensitive data processed by the browser or email client, and potential for further lateral movement within a network. The CVSS score reflects high impacts across all three security dimensions (Mozilla Advisory mfsa2025-94).

Exploitability

There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is approximately 0.04%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Mozilla rates the exploitability as requiring significant effort due to the nature of memory safety bugs (Mozilla Advisory mfsa2025-92).

Mitigation and workarounds

Mozilla has released patched versions addressing CVE-2025-14333: Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird ESR 140.6. Users and administrators should update all affected Mozilla products to these versions or later immediately. No configuration-based workarounds are available; upgrading is the only remediation. Enterprise administrators should prioritize patching Firefox ESR and Thunderbird ESR deployments, as these are commonly used in managed environments (Mozilla Advisory mfsa2025-92, Mozilla Advisory mfsa2025-94).

Community reactions

Multiple Linux distributions including Red Hat, Debian, Oracle Linux, Rocky Linux, AlmaLinux, SUSE, and Slackware issued security advisories and updated packages for Firefox and Thunderbird following Mozilla's disclosure. The CIS (Center for Internet Security) also published an advisory noting that multiple vulnerabilities in Mozilla products could allow for arbitrary code execution. Coverage was largely routine, consistent with Mozilla's regular security release cycle, with no exceptional community alarm given the moderate severity rating and lack of known exploitation (Mozilla Advisory mfsa2025-92).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

thunderbird: 1:140.6.0esr-1~deb12u1

Fixed

sid

thunderbird: 1:140.6.0esr-1

Fixed

trixie

thunderbird: 1:140.6.0esr-1~deb13u1

Fixed

Ubuntu

Fixed

bionic (esm-apps)

mozjs38

Unknown

devel

firefox

Not Affected

jammy

thunderbird: 1:140.7.1+build1-0ubuntu0.22.04.1

Fixed

noble

firefox

Not Affected

questing

firefox

Not Affected

resolute

firefox

Not Affected

RHEL / CentOS

Fixed

RHEL 8

:appstream:firefox-0:140.6.0-1.el8_10.src

Fixed

RHEL 9

:appstream:firefox-0:140.6.0-1.el9_0.src

Fixed

RHEL 10

firefox-0:140.6.0-1.el10_0.src

Fixed

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management