CVE-2025-13017
8.1HIGHSame-origin policy bypass in the DOM: Notifications component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Thunderbird < 145, and Thunderbird < 140.5.
Publicado: 11/11/2025Actualizado: 11/19/2025
Descripción
Same-origin policy bypass in the DOM: Notifications component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Thunderbird < 145, and Thunderbird < 140.5.
Análisis IAImpulsado por IA
Productos Afectados
mozillafirefox
mozillafirefox
Referencias
- https://bugzilla.mozilla.org/show_bug.cgi?id=1980904Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2025-87/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-88/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-90/
- https://www.mozilla.org/security/advisories/mfsa2025-91/