CVE-2025-3523
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Published Apr 15, 2025
CWE ID 451
Summary
CVE-2025-3523 is a vulnerability affecting Thunderbird versions below 137.0.2 and 128.9.2. When handling emails with multiple attachments that contain external links via the X-Mozilla-External-Attachment-URL header, only the last link's hover text is displayed to users. Although the correct link is used upon clicking an attachment, the misleading hover text poses a risk of tricking users into downloading content from untrusted sources. This issue could potentially lead to security threats if users unknowingly download malicious content.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mozilla Thunderbird
Affected Vendors
- Mozilla