CVE-2025-6424: Mozilla Firefox

Critical severity, CVSS 9.8. EPSS: 4.4% chance of exploitation in the next 30 days.

A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.

Affected products

  • Mozilla Firefox: before 115.25.0 (fixed in 115.25.0); before 140.0 (fixed in 140.0); from 116.0, before 128.12.0 (fixed in 128.12.0)

Published 2025-06-24. Last modified 2026-10-05.