CVE-2025-3033

Publication date

2025-04-01 12:29:04

Family

mozilla

State

PUBLISHED

Description

After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 137 and Thunderbird < 137.