Security Advisory

CVE-2025-3033

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-04-01 12:29:04
Last updated 2026-04-13 14:29:35
Assigner mozilla
State PUBLISHED

Description

After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 137 and Thunderbird 137.