Cross-Origin Leak Vulnerability in Firefox Browser Software by Mozilla
CVE-2025-5263

4.3MEDIUM

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
27 May 2025

What is CVE-2025-5263?

This vulnerability arises from improper error handling in script execution, which fails to adequately isolate such processes from web content. As a result, it can potentially facilitate cross-origin leak attacks, allowing malicious entities to gain unauthorized access to sensitive information from other domains. The affected versions include Firefox below 139 and specific ESR versions, highlighting the need for immediate updates to safeguard user data and maintain secure browsing.

Affected Version(s)

Firefox < 139

Firefox ESR < 115.24

Firefox ESR < 128.11

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

terjanq
.
The Cyber Security Vulnerability Database.