CVE-2025-14325Disclosure(mozilla / firefox)

LOWCVSS 7.3 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for mozilla firefox systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox
  • thunderbird

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-28); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
firefoxthunderbird

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-28: 2Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1Mentions · 2026-04-28: 1PoC Mentioned / Linked · 2026-03-28: 1PoC Mentioned / Linked · 2026-03-31: 1PoC Mentioned / Linked · 2026-04-28: 1Exploit Tool / Code · 2026-03-28: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-28: 103-2803-3003-3104-28
Signal classification4 categories
Disclosure
240.0%
Exploit
120.0%
General
120.0%
PoC
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-282
Exploit1General1
2026-03-301
Disclosure1
2026-03-311
PoC1
2026-04-281
Disclosure1
Full discourse5 posts
  • Lan Vu 🇻🇳@lanleft_
    General

    Check out my latest blog post. I hope you all enjoy it 👉👈 https://qriousec.github.io/post/cve-2025-14325/

    Post summary

    The tweet simply points to a blog post about CVE-2025-14325 without providing evidence of exploit availability, active use, patches, or technical specifics.

    546024411914.6K
    1.5K followersView on X
  • Qrious Secure@qriousec
    Exploit

    Technical details on exploiting Firefox 0day we found last year by AI-assisted fuzzing. by @lanleft_ https://qriousec.github.io/post/cve-2025-14325/

    Post summary

    The post shares technical exploitation details and likely PoC code for Firefox CVE‑2025‑14325 discovered through AI-assisted fuzzing, but it does not discuss active attacks, patches, or debunking.

    032014711216.9K
    2.2K followersView on X
  • Mr. OS@ksg93rd
    PoC

    #exploit #AppSec 1⃣ CVE-2026-4946: https://takeonme.org/cves/cve-2026-4946 NSA Ghidra Auto-Analysis Annotation Command Execution // A novel and highly effective attack against reverse engineers and malware analysts. By embedding malicious annotation payloads into distributed binaries, an attacker can reliably achieve code execution on the systems of analysts who inspect those binaries in Ghidra 2⃣ CVE-2025-14325: https://qriousec.github.io/post/cve-2025-14325/ SpiderMonkey Type Confusion in Baseline JIT Inline Cache // A type confusion in SpiderMonkey's JIT inline cache that enables arbitrary memory access and RCE through heap leaks and memory overlapping exploits during property operations

    Post summary

    The post highlights two CVEs, links to detailed pages likely containing proof‑of‑concept code, and provides technical details of the vulnerabilities but does not mention active exploitation or patches.

    01021249
    3.2K followersView on X
  • Blue Team News@blueteamsec1
    Disclosure

    CVE-2025-14325: SpiderMonkey Type Confusion in Baseline JIT Inline Cache - found via AI assisted fuzzing http://dlvr.it/TSGnlY #cyber #threathunting #infosec

    Post summary

    The tweet announces the discovery of CVE-2025-14325, a type confusion flaw in Firefox’s SpiderMonkey JIT engine, and provides a link to further details, but offers no exploit, patch, or active abuse information.

    000001.0K
    55.8K followersView on X
  • motikan2010@motikan2010
    Disclosure

    2026-03-28 の人気記事はコチラでした。(自動ツイート) #Hacker_Trends ――― CVE-2025-14325: SpiderMonkey Type Confusion in Baseline JIT Inline Cache https://hacker-trends.motikan2010.com/2026-03-28#f0679db2749b2d85f0f910abee56833e https://t.co/fvlXnV0877

    Post summary

    The tweet references CVE‑2025‑14325, shares a link to an article, and provides a brief technical description, but offers no proof‑of‑concept, exploit details, or patch information.

    00000268
    1.4K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox---
Appmozillafirefox---
Appmozillathunderbird---
Appmozillathunderbird---

Explore more