CVE-2025-4085

Publication date

2025-04-29 13:13:39

Family

mozilla

State

PUBLISHED

Description

An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. This vulnerability affects Firefox < 138 and Thunderbird < 138.