FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Mozilla -- Information leak

Affected packages
firefox < 138.0,2
thunderbird < 138.0

Details

VuXML ID 9fa8c4a2-2e85-11f0-a989-b42e991fc52e
Discovery 2025-04-29
Entry 2025-05-11

security@mozilla.org reports:

An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges.

References

CVE Name CVE-2025-4085
URL https://nvd.nist.gov/vuln/detail/CVE-2025-4085