Mozilla · Firefox · CVE-2025-13024
**Name of the Vulnerable Software and Affected Versions**
Mozilla Firefox versions prior to 145
Thunderbird versions prior to 145
**Description**
The issue is a JIT miscompilation within the JavaScript Engine's JIT component, leading to a potential out-of-bounds write in memory. This could allow a remote attacker to execute arbitrary code. The vulnerability was reported by Project KillFuzz of Qrious Secure.
**Recommendations**
Mozilla Firefox versions prior to 145: Update to version 145 or later.
Thunderbird versions prior to 145: Update to version 145 or later.