Security Advisory
CVE-2025-3033
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 137 and Thunderbird 137.