CVE-2025-14321PoC(mozilla / firefox)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch mozilla firefox systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox
  • thunderbird

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-02-02); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
firefoxthunderbird

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-02: 1Mentions · 2026-02-06: 1PoC Mentioned / Linked · 2026-02-02: 1Patch / Workaround · 2026-02-06: 1Technical Details · 2026-02-02: 102-0202-06
Signal classification2 categories
PoC
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-021
PoC1
2026-02-061
Patch1
Full discourse2 posts
  • Blackstorm Security@blackstormsecbr
    PoC

    Firefox / WebRTC Encoded Transforms: UAF via undetached ArrayBuffer / CVE-2025-14321: https://aisle.com/blog/firefox-webrtc-encoded-transforms-uaf-via-undetached-arraybuffer-cve-2025-14321 #vulnerability #cybersecurity #informationsecurity #firefox #exploitation

    Post summary

    A blog post discloses a Use-After-Free vulnerability in Firefox’s WebRTC encoded transforms (CVE-2025-14321) and likely includes a PoC, but it does not mention active exploitation, patches, or a false-positive assessment.

    014069355.4K
    1.8K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 Attention #openSUSE Tumbleweed Users & System Admins! 🚨 A new security update is live, patching vulnerability CVE-2025-14321 in the cockpit-machines package. Read more: 👉 https://tinyurl.com/325jehsn #Security https://t.co/OSbUoEcTBo

    Post summary

    OpenSUSE Tumbleweed users are notified that a live security update patches CVE-2025-14321 in the cockpit-machines package. No exploit or PoC details are provided.

    0000065
    1.3K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox---
Appmozillafirefox---
Appmozillathunderbird---
Appmozillathunderbird---

Explore more