Security Advisory
CVE-2025-5266
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.