Mozilla Firefox and Firefox ESR Use-After-Free Vulnerability in FontFaceSet Allowing Potentially Exploitable Crash

Vulnerability

A use-after-free vulnerability has been identified in the FontFaceSet component of Mozilla Firefox and Firefox Extended Support Release (ESR). This vulnerability can lead to a crash that may be exploitable. It affects Firefox versions prior to 140, as well as Firefox ESR versions prior to 115.25 and 128.12.

Impact

Exploitation of this vulnerability can cause a crash, with the potential for exploitation to execute arbitrary code.

Remediation

Users can upgrade to Firefox 140 or Firefox ESR 115.25 or 128.12 to address this vulnerability.

Added: Jun 24, 2025, 1:30 PM
Updated: Jun 24, 2025, 1:30 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.