CVE-2025-0237

MEDIUM

Firefox <134, Thunderbird <128.6 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

Scores

CVSS v3 5.4
EPSS 0.0012
EPSS Percentile 30.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (7)
mozilla/firefox < 128.6.0
mozilla/firefox < 134.0
Mozilla/Firefox 128.6 - 128.*
Mozilla/Firefox 134
mozilla/thunderbird < 128.6.0
Mozilla/Thunderbird 128.6 - 128.*
Mozilla/Thunderbird 134
Published Jan 07, 2025
Tracked Since Feb 18, 2026