CVE-2025-5266

Publication date

2025-05-27 12:29:25

Family

mozilla

State

PUBLISHED

Description

Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.