CRITICAL

CVE-2025-11708

Mozilla Firefox 2025-10-14 CVSS v3.1
CVSS
9.8

Description

Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

Summary dbcve.org

A use-after-free vulnerability in MediaTrackGraphImpl::GetInstance() allows remote attackers to execute arbitrary code via crafted web content that triggers improper memory management in the media tracking graph implementation. This is a critical memory safety flaw in Firefox and Thunderbird's media handling subsystem.

Mitigation

Upgrade to Firefox 144+, Firefox ESR 140.4+, Thunderbird 144+, or Thunderbird 140.4+ to remediate. No effective network-level workarounds exist for client-side browser vulnerabilities.

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

0.51%
Probability of exploitation in next 30 days
42.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE