CVE-2025-0237
published 2025-01-07CVE-2025-0237: The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal…
medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 134.0-1 (sid) | firefox 134.0-1 (sid) |
| debian | firefox-esr | < firefox 134.0-1 (sid) | firefox 134.0-1 (sid) |
| debian | thunderbird | < firefox 134.0-1 (sid) | firefox 134.0-1 (sid) |
| mozilla | firefox | < 128.6.0 | 128.6.0 |
| mozilla | firefox | < 134.0 | 134.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 134.0+build1-0ubuntu0.20.04.1 | 134.0+build1-0ubuntu0.20.04.1 |
| mozilla | thunderbird | < 128.6.0 | 128.6.0 |
| mozilla | thunderbird | >= 0 < 1:128.6.0esr-1~deb11u1 | 1:128.6.0esr-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:128.6.0esr-1~deb12u1 | 1:128.6.0esr-1~deb12u1 |
| mozilla | thunderbird | >= 0 < 1:128.6.0esr-1 | 1:128.6.0esr-1 |
| mozilla | thunderbird | >= 0 < 1:128.6.0esr-1 | 1:128.6.0esr-1 |
| mozilla | thunderbird | >= 129.0 < 134.0 | 134.0 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
osv5.4MEDIUM
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2026-02-02
CVE-2025-8031 Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2025-01-09·CVSS 5.4
CVE-2025-0240 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2025-0237,
CVE-2025-0239, CVE-2025-0240, CVE-2025-0242, CVE-2025-0243, CVE-2025-0247)
Irvan Kurniawan discovered that Firefox incorrectly handled memory when
breaking lines in text, leading to a use-after-free vulnerability. An
attacker could possibly use this issue to cause a denial of service or
possibly execute arbitrary code. (CVE-2025-0238)
Nils Bars discovered that Firefox incorrectly handled memory when using
JavaScript Text Segm
Red Hat
firefox: thunderbird: WebChannel APIs susceptible to confused deputy attack
vendor_redhat·2025-01-07·CVSS 5.4
CVE-2025-0237 [MEDIUM] CWE-441 firefox: thunderbird: WebChannel APIs susceptible to confused deputy attack
firefox: thunderbird: WebChannel APIs susceptible to confused deputy attack
The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue: The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks.
Statement: Red Hat Product Security rates the severity of this flaw as
Debian
CVE-2025-0237: firefox - The WebChannel API, which is used to transport various information across proces...
vendor_debian·2025·CVSS 5.4
CVE-2025-0237 [MEDIUM] CVE-2025-0237: firefox - The WebChannel API, which is used to transport various information across proces...
The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.
Scope: local
sid: resolved (fixed in 134.0-1)
Mozilla
Mozilla Foundation Security Advisory 2025-01: CVE-2025-0237
vendor_mozilla·CVSS 5.4
CVE-2025-0237 [MEDIUM] Mozilla Foundation Security Advisory 2025-01: CVE-2025-0237
Mozilla Foundation Security Advisory 2025-01
CVE: CVE-2025-0237
Product: Firefox
Impact: high
Fixed in: Firefox 134
Mozilla
Mozilla Foundation Security Advisory 2025-02: CVE-2025-0237
vendor_mozilla·CVSS 5.4
CVE-2025-0237 [MEDIUM] Mozilla Foundation Security Advisory 2025-02: CVE-2025-0237
Mozilla Foundation Security Advisory 2025-02
CVE: CVE-2025-0237
Product: Firefox ESR
Impact: moderate
Fixed in: Firefox ESR 128.6
Mozilla
Mozilla Foundation Security Advisory 2025-05: CVE-2025-0237
vendor_mozilla·CVSS 5.4
CVE-2025-0237 [MEDIUM] Mozilla Foundation Security Advisory 2025-05: CVE-2025-0237
Mozilla Foundation Security Advisory 2025-05
CVE: CVE-2025-0237
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 128.6
Mozilla
Mozilla Foundation Security Advisory 2025-04: CVE-2025-0237
vendor_mozilla·CVSS 5.4
CVE-2025-0237 [MEDIUM] Mozilla Foundation Security Advisory 2025-04: CVE-2025-0237
Mozilla Foundation Security Advisory 2025-04
CVE: CVE-2025-0237
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 134
VulDB
Mozilla Firefox up to 133.x WebChannel API authorization (Nessus ID 213532)
vuldb·2026-04-15·CVSS 5.4
CVE-2025-0237 [MEDIUM] Mozilla Firefox up to 133.x WebChannel API authorization (Nessus ID 213532)
A vulnerability labeled as problematic has been found in Mozilla Firefox up to 133.x. Affected is an unknown function of the component WebChannel API. Executing a manipulation can lead to incorrect authorization.
This vulnerability appears as CVE-2025-0237. The attacker needs to be present on the local network. There is no available exploit.
The affected component should be upgraded.
OSV
firefox vulnerabilities
osv·2025-01-09·CVSS 5.4
CVE-2025-0237 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2025-0237,
CVE-2025-0239, CVE-2025-0240, CVE-2025-0242, CVE-2025-0243, CVE-2025-0247)
Irvan Kurniawan discovered that Firefox incorrectly handled memory when
breaking lines in text, leading to a use-after-free vulnerability. An
attacker could possibly use this issue to cause a denial of service or
possibly execute arbitrary code. (CVE-2025-0238)
Nils Bars discovered that Firefox incorrectly handled memory when using
JavaScript Text Segmentation. An attacker could possibly use this issue to
cause a d
GHSA
GHSA-2776-h8x3-vrr7: The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the princ
ghsa_unreviewed·2025-01-07
CVE-2025-0237 [MEDIUM] CWE-863 GHSA-2776-h8x3-vrr7: The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the princ
The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.
OSV
CVE-2025-0237: The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the princ
osv·2025-01-07·CVSS 5.4
CVE-2025-0237 [MEDIUM] CVE-2025-0237: The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the princ
The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1915257https://www.mozilla.org/security/advisories/mfsa2025-01/https://www.mozilla.org/security/advisories/mfsa2025-02/https://www.mozilla.org/security/advisories/mfsa2025-04/https://www.mozilla.org/security/advisories/mfsa2025-05/https://lists.debian.org/debian-lts-announce/2025/01/msg00004.html
2025-01-07
Published