CVE-2025-0237

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 7, 2025
Updated: Jan 13, 2025
CWE ID 863

Summary

CVE-2025-0237 is a vulnerability affecting the WebChannel API in Firefox versions below 134 and Firefox ESR below 128.6, as well as Thunderbird versions below 134 and Thunderbird below 128.6. The WebChannel API, which facilitates inter-process communication, failed to verify the sending principal, leading to a privilege escalation risk. Attackers could potentially exploit this flaw to gain elevated access and execute malicious code. This vulnerability poses a serious threat and requires immediate attention from users to update their affected browsers.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mozilla Thunderbird
  • Mozilla Firefox
  • Mozilla Firefox ESR

Affected Vendors

  • Mozilla