CVE-2025-14321
CRITICALFirefox < 146.0 and 140.6-140.* - Use-After-Free in WebRTC Signaling
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-14321. PoCs published by h3raklez.
AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2025-14321, a Use-After-Free (UAF) vulnerability in Firefox's WebRTC Encoded Transforms API. The exploit demonstrates heap corruption via dangling pointers in ArrayBuffers, leading to a tab crash in vulnerable Firefox versions.
Description
Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
Exploits (1)
This repository contains a proof-of-concept exploit for CVE-2025-14321, a Use-After-Free (UAF) vulnerability in Firefox's WebRTC Encoded Transforms API. The exploit demonstrates heap corruption via dangling pointers in ArrayBuffers, leading to a tab crash in vulnerable Firefox versions.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H