CVE-2025-1013

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 4, 2025
CWE ID 362

Summary

CVE-2025-1013 is a race condition vulnerability that affects Firefox versions below 135, Firefox ESR below 128.7, Thunderbird versions below 128.7, and Thunderbird versions below 135. This issue could lead to private browsing tabs being inadvertently opened in normal browsing windows, potentially resulting in a privacy leak. The race condition refers to a sequence of events where two or more processes or threads access shared resources in a way that could lead to inconsistent or incorrect results, which in this case, allows for the opening of private browsing tabs in normal windows. Users are advised to update their browsers to mitigate this vulnerability and protect their privacy.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mozilla Thunderbird
  • Mozilla Firefox

Affected Vendors

  • Mozilla