[CIVN-2025-0378] Multiple Vulnerabilities in Mozilla Products

By Published On: December 19, 2025

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Mozilla Products 
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Mozilla Firefox versions prior to 146.0.1
Overview
Multiple vulnerabilities have been reported in Mozilla products which could allow an attacker to execute arbitrary code or cause a denial-of-service condition on the targeted system.
Target Audience:
All end-user organizations and individuals using Mozilla Products.
Risk Assessment:
High risk of unauthorized access to sensitive information.
Impact Assessment:
Potential for data theft, sensitive information disclosure and complete compromise of system.
Description
Mozilla Firefox is a free and open-source web browser developed by Mozilla foundation.
Multiple vulnerabilities exist in Mozilla products due to Use-after-free in the Disability Access APIs component and Memory safety bugs. A remote attacker could exploit these vulnerabilities by convincing the victim to open a specially crafted web request.
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code or cause a denial-of-service on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://www.mozilla.org/en-US/security/advisories/mfsa2025-98/
References
Mozilla
https://www.mozilla.org/en-US/security/advisories/mfsa2025-98/
CVE Name
CVE-2025-14860
CVE-2025-14861
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmlFW14ACgkQ3jCgcSdc
ys9ZMw//TdH1O9NOEaKrMhRCC8KirDo/rWPhPFkvmlq6fnILBNbWSBdNhkBlTwHx
qL+I8/sGdFeWOJGAdqlU6rgDmyKJeLbg0izKUdMBvzRLtZ2ArKrHooEWvMHnoEH7
hVk6dtXmLxLTvknWg5FznE8+uH3zh8Br7aw9vwquC110vlqkxPEG41S62nUH30J6
kvdl8AaC8RqyOCk8Gc4R0TvfpqIuF+tVNC/cdDGh2xyxBvIwJtT9K3ucK1SLcjbT
HKHosWa4zLRnHRlvMQjJCxfRs5DxdA5V8jKmOqSZbej7tVz81pt1Hjk0EOGNmYIG
/pHGe+VQyfjgBWA7IlmkFZPvNMVUVykFgKdbPPS8qCcALRCQQYu9UB9139LH0QBb
u6k019uFTj8MqrI7eyotxdT59v2LxqWeAUBo50P2ZbI46sKBcLc+k/qsgPaz8VE/
SFA1iXybgPXZeWDrMWxcrNZQP+VA+eDjrzezNe6lfPEvaPUwrqU7l424APLiYLA5
BwJoJJvHTF5BjDmlKuYLo0sztauyidKE99EGD99F7KqMVWcJEN7CQEq4prbo9mlP
xuiqpdUTPzLWCsMnBDdbNXxzcUbDPjagz6c+PvmhraazkYqfKycmzIBmfyjii72Q
AzIOTnL81JIQQxc0EcpVQ9PHkcqiLFBmqYe+vJC2lHlJtZ6vBR8=
=Y/TO
—–END PGP SIGNATURE—–

Share this article