CVE-2025-3523

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Apr 15, 2025
CWE ID 451

Summary

CVE-2025-3523 is a vulnerability affecting Thunderbird versions below 137.0.2 and 128.9.2. When handling emails with multiple attachments that contain external links via the X-Mozilla-External-Attachment-URL header, only the last link's hover text is displayed to users. Although the correct link is used upon clicking an attachment, the misleading hover text poses a risk of tricking users into downloading content from untrusted sources. This issue could potentially lead to security threats if users unknowingly download malicious content.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mozilla Thunderbird

Affected Vendors

  • Mozilla