← Back to browse · API

CVE-2025-6424

Severity
CRITICAL
CVSS
9.8
EPSS
0.03214
Risk score
40.32
CISA KEV
No
PoC
No
Published
2025-06-24
Modified
2026-04-13
First seen
2026-08-07
Aliases
EUVD-2025-19086, GHSA-87C4-94W2-RW7J
Products
-
Sources
euvd EUVD-2025-19086

Description

A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.

References