External risk intelligence

Firefox Thunderbird JIT Miscompilation Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-14330

This vulnerability affects the JIT component of a web browser and email client. While these applications interact with the internet, the vulnerable component is a client-side engine. It is not an internet-facing service, edge gateway, or server-side application that is exposed to public network traffic in a typical deployment, making it a client-side execution risk rather than an exposed surface.

Memory Corruption

Mozilla Firefox

before 140.6.0before 146.0

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security vulnerability has been identified in the JavaScript engine used by Mozilla Firefox and Thunderbird. This issue could allow for significant compromise of affected systems.

  • Flaw in browser's code execution.
  • High impact if exploited.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by tricking a user into visiting a malicious website or opening a compromised email. This would cause the browser's or email client's JavaScript engine to misinterpret code, potentially leading to a crash or remote code execution.

  • Requires no authentication or user privileges.
  • Triggered by user interaction with malicious content.
  • Leads to high impact on confidentiality, integrity, and availability.

Live Threat

Current exploitation, exposure, and threat context

A miscompilation in the JavaScript engine could allow an attacker to execute arbitrary code, potentially affecting system data and service behavior when a user interacts with malicious content.

  • System data and service integrity.
  • Via malicious JavaScript execution.
  • Arbitrary code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Firefox and Thunderbird's JavaScript engine likely falls under the purview of application owners and potentially platform teams if these applications are managed centrally. The first step is to inventory all instances of affected software, determine their business criticality, and identify the accountable owners before planning any remediation.

  • Application owners should assume responsibility.
  • Verify all Firefox and Thunderbird installations.
  • Coordinate updates during planned maintenance.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the JavaScript Engine in Firefox and Thunderbird?

It is a core component within these applications responsible for translating JavaScript code into machine-executable instructions. This Just-In-Time (JIT) compilation process optimizes performance by executing code directly at runtime. Because it handles complex scripts from web pages or email content, it must strictly manage memory and data structures to ensure the underlying system remains secure during execution.

What does JIT miscompilation mean for CVE-2025-14330?

This flaw relates to how the engine processes code, categorized under weaknesses involving improper restriction of operations within memory boundaries. Specifically, the engine may misinterpret or mishandle the compiled instructions, leading to memory corruption. This instability can be leveraged to deviate from the application's intended logic, potentially allowing unauthorized actions to run on the host system.

How is this vulnerability triggered by an attacker?

An attacker triggers this by enticing a user to interact with specifically crafted malicious content, such as a compromised website or a booby-trapped email. The vulnerability is not triggered by standard, benign web browsing or legitimate email use. The engine's failure occurs only when it attempts to parse and compile the specially manipulated script provided by the attacker during a session.

Is this vulnerability relevant to my network perimeter?

According to Halo Surface Signal, this is not an internet-facing service or server-side application. Because the risk resides in a client-side engine, it is classified as a local execution threat rather than a network-exposed service. Relevance depends on whether your endpoints—where users actively browse the web and read emails—are running the unpatched versions of Firefox or Thunderbird.

Do I need to update my browser and email client?

Yes, if you use these applications, you should plan to update to the versions where this was fixed, specifically Firefox 146 or ESR 140.6, and Thunderbird 146 or ESR 140.6. Begin by identifying all systems running these programs in your environment. Once inventoried, coordinate with application owners to deploy these updates, as they contain the necessary code corrections to prevent the JIT engine from miscompiling scripts.

References