Log Exposure Vulnerability in Firefox for Android and Thunderbird
CVE-2025-4090

6.5MEDIUM

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
29 April 2025

What is CVE-2025-4090?

A log exposure vulnerability was discovered in Firefox for Android and Thunderbird, where sensitive library locations were inadvertently logged through Logcat. This flaw could potentially expose private information about users' libraries and sensitive data, affecting user privacy and security. It impacts versions prior to 138 of both Firefox for Android and Thunderbird, highlighting the importance of updating to secure versions to mitigate risks.

Affected Version(s)

Firefox < 138

Thunderbird < 138

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Seongyun Jeong
.