File Content Disclosure Vulnerability in Mozilla Firefox
CVE-2025-1936
7.3HIGH
What is CVE-2025-1936?
This vulnerability in Mozilla Firefox allows attackers to retrieve local file content from ZIP archives. By manipulating URLs with jar: protocols, it exploits how null characters and extensions are processed, enabling harmful code to be disguised as legitimate content such as images. This poses a risk, as the exploited web extensions can potentially reveal sensitive information or execute unauthorized scripts.
Affected Version(s)
Firefox < 136
Firefox ESR < 128.8
Thunderbird < 136