FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Mozilla -- XS-leak attack

Affected packages
firefox-esr < 128.11.0
firefox < 139.0,2

Details

VuXML ID 61be5684-4222-11f0-976e-b42e991fc52e
Discovery 2025-05-27
Entry 2025-06-05

security@mozilla.org reports:

Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks.

References

CVE Name CVE-2025-5266
URL https://nvd.nist.gov/vuln/detail/CVE-2025-5266