Home 138 (rpm)
unaffected
138 (rpm)
unaffected
Description
An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
Product status
Credits
Andrew McCreight
References
bugzilla.mozilla.org/show_bug.cgi?id=1915280
www.mozilla.org/security/advisories/mfsa2025-28/
www.mozilla.org/security/advisories/mfsa2025-31/