File Content Disclosure Vulnerability in Mozilla Firefox
CVE-2025-1936
Currently unrated
Summary
This vulnerability in Mozilla Firefox allows attackers to retrieve local file content from ZIP archives. By manipulating URLs with jar: protocols, it exploits how null characters and extensions are processed, enabling harmful code to be disguised as legitimate content such as images. This poses a risk, as the exploited web extensions can potentially reveal sensitive information or execute unauthorized scripts.
Affected Version(s)
Firefox < 136
Firefox ESR < 128.8
References
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Surya Dev Singh