An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. This vulnerability affects Firefox < 138 and Thunderbird < 138.
History

Tue, 29 Apr 2025 13:30:00 +0000

Type Values Removed Values Added
Description An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. This vulnerability affects Firefox < 138 and Thunderbird < 138.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2025-04-29T13:13:39.469Z

Updated: 2025-04-30T03:56:30.604Z

Reserved: 2025-04-29T13:13:38.767Z

Link: CVE-2025-4085

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-04-29T14:15:35.187

Modified: 2025-04-29T14:15:35.187

Link: CVE-2025-4085

cve-icon Redhat

No data.