Firefox 145 Released: Urgent Security Update Patches Critical Vulnerabilities

Listen to this Post

Featured Image
Mozilla has rolled out Firefox 145 on November 11, 2025, with a crucial security update aimed at addressing severe vulnerabilities that could allow attackers to execute arbitrary code on users’ devices. This release patches 16 Common Vulnerabilities and Exposures (CVEs) affecting key components such as graphics, JavaScript, and the Document Object Model (DOM), with eight flagged as high severity. The most critical of these issues, CVE-2025-13027, was identified by Mozilla’s Fuzzing Team in Firefox 144 and Thunderbird 144, revealing memory corruption patterns that could be exploited for remote code execution. These flaws are capable of bypassing browser sandboxes, potentially putting entire systems at risk.

Summary of Firefox 145 Security Issues

The update highlights several high-risk vulnerabilities, particularly in graphics processing and WebGPU components. Security researchers Atte Kettunen and Oskar L uncovered flaws (CVE-2025-13021, CVE-2025-13022, CVE-2025-13025) related to incorrect boundary conditions in WebGPU processing, which could lead to out-of-bounds memory access, crashes, or malicious code injection. More alarming are CVE-2025-13023 and CVE-2025-13026, which allow sandbox escapes, giving attackers potential access to sensitive system resources.

JavaScript engine vulnerabilities also feature prominently. CVE-2025-13016 addresses boundary errors in WebAssembly, while CVE-2025-13024 involves Just-In-Time (JIT) miscompilation that could accelerate execution of harmful code. Additional issues include a graphics race condition (CVE-2025-13012) and moderate-impact vulnerabilities like same-origin policy bypasses in DOM components (CVE-2025-13017, CVE-2025-13019), mitigation bypasses (CVE-2025-13018, CVE-2025-13013), and WebRTC use-after-free errors (CVE-2025-13020, CVE-2025-13014), which could expose audio or video streams. A few low-severity issues, such as UI spoofing (CVE-2025-13015), were also addressed.

Although Mozilla reports no confirmed exploitation in the wild, the high severity of these vulnerabilities makes immediate updates essential. Users still on older versions of Firefox face elevated risks from drive-by downloads, phishing, and targeted attacks. To ensure security, Firefox 145 should be installed immediately, either via mozilla.org or through automatic update features.

What Undercode Say:

The release of Firefox 145 underscores the growing complexity of modern browser security. WebGPU, designed to bring high-performance graphics to web applications, is becoming a double-edged sword—its sophisticated capabilities also make it an attractive target for attackers. Memory corruption issues in CVE-2025-13027 illustrate a persistent challenge in modern software: even extensively tested code can harbor subtle bugs that allow remote exploitation. This patch highlights the importance of fuzz testing and the role of automated vulnerability discovery, which are now integral to maintaining browser security.

The JavaScript engine’s vulnerabilities reveal another layer of risk. JIT miscompilation and WebAssembly boundary errors show that even performance optimizations intended to accelerate user experience can inadvertently create execution paths for malicious actors. Similarly, race conditions in graphics processing (CVE-2025-13012) demonstrate timing-based attack vectors that are difficult to predict and mitigate.

Moderate-impact vulnerabilities, though less immediately threatening, are significant in aggregate. Same-origin policy bypasses and mitigation circumventions could allow attackers to chain exploits, turning minor bugs into full-scale attacks. The WebRTC issues, while classified as low severity, could still compromise privacy, leaking sensitive audio and video data if combined with other flaws.

For enterprises and security-conscious users, this update is a reminder that maintaining browser security requires proactive patch management. Organizations should prioritize patch deployment, test critical web applications against the new version, and monitor for unusual behavior that may indicate attempted exploitation. Firefox 145 also reinforces the importance of educating users about safe browsing habits, as social engineering remains a common vector even in a fully patched environment.

From a technical perspective, Firefox’s rapid response in identifying and patching 16 CVEs in a single release demonstrates robust internal security processes. Mozilla’s Fuzzing Team continues to show the effectiveness of automated bug discovery, yet the prevalence of high-severity flaws suggests that even modern, mature software must remain under constant scrutiny. Future browser versions will likely continue to face similar risks as web standards evolve and new APIs like WebGPU gain wider adoption.

Fact Checker Results:

✅ Firefox 145 released on November 11, 2025

✅ 16 CVEs addressed, 8 high severity

❌ No confirmed exploitation in the wild reported

Prediction:

📊 As WebGPU adoption grows, browser graphics vulnerabilities may become a prime target for attackers.
📊 Expect increased focus on automated fuzzing and AI-assisted vulnerability detection in upcoming Firefox releases.
📊 Users delaying updates risk exposure to sophisticated remote code execution attacks.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.twitter.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon