← Back to CVE List

CVE-2025-0237

Published: 2025-01-07T16:15Z
Last Modified: 2025-04-03T16:29Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt