CVE-2025-9180
published 2025-08-19CVE-2025-9180: Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR…
high8.1CVSS 3.1
AVNACLPRNUIRSUCHIHAN
Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 142.0-1 (sid) | firefox 142.0-1 (sid) |
| debian | firefox-esr | < firefox 142.0-1 (sid) | firefox 142.0-1 (sid) |
| debian | thunderbird | < firefox 142.0-1 (sid) | firefox 142.0-1 (sid) |
| linux | linux_kernel | >= 3.16.0 < 6.17.3 | 6.17.3 |
| mozilla | firefox | < 115.27.0 | 115.27.0 |
| mozilla | firefox | < 142.0 | 142.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 128.0 < 128.14.0 | 128.14.0 |
| mozilla | firefox | >= 140.0 < 140.2.0 | 140.2.0 |
| mozilla | thunderbird | < 128.14.0 | 128.14.0 |
| mozilla | thunderbird | < 142.0 | 142.0 |
| mozilla | thunderbird | >= 0 < 1:128.14.0esr-1~deb11u1 | 1:128.14.0esr-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:128.14.0esr-1~deb12u1 | 1:128.14.0esr-1~deb12u1 |
| mozilla | thunderbird | >= 0 < 1:128.14.0esr-1~deb13u1 | 1:128.14.0esr-1~deb13u1 |
| mozilla | thunderbird | >= 0 < 1:128.14.0esr-1 | 1:128.14.0esr-1 |
| mozilla | thunderbird | >= 140.0 < 140.2.0 | 140.2.0 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
osv8.1HIGH