CVE-2025-0237
The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.
Vendor
Product
CWE
Yayın Tarihi
2025-01-07 16:15:38
Güncelleme
2025-11-03 23:17:34
Source Identifier
security@mozilla.org
KEV Date Added
-
Kategoriler
Referanslar
https://bugzilla.mozilla.org/show_bug.cgi?id=1915257
https://www.mozilla.org/security/advisories/mfsa2025-01/
https://www.mozilla.org/security/advisories/mfsa2025-02/
https://www.mozilla.org/security/advisories/mfsa2025-04/
https://www.mozilla.org/security/advisories/mfsa2025-05/
https://lists.debian.org/debian-lts-announce/2025/01/msg00004.html