CVE-2025-8039
8.1Mozilla · Firefox, Thunderbird
A vulnerability in Mozilla Firefox and Thunderbird allowed search terms to persist in the URL bar after navigating away from search pages, posing a risk of information leakage.
Executive summary
Mozilla Firefox and Thunderbird contain a vulnerability where search terms persist in the URL bar after navigation, potentially exposing sensitive user data to unauthorized parties.
Vulnerability
The vulnerability involves an improper handling of URL state where search terms remain visible in the browser address bar after a user has navigated away from the search interface. This is an unauthenticated vulnerability requiring user interaction (UI:R) to trigger the persistence issue.
Business impact
The retention of search terms in the URL bar constitutes a significant privacy risk, as sensitive queries could be captured by browser extensions, history logs, or shoulder-surfing attackers. With a CVSS score of 8.1, the high severity reflects the potential for unauthorized access to sensitive user information (C:H) and integrity compromise (I:H) within the browser environment.
Remediation
Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 141 or the ESR 140.1 release immediately.
Proactive Monitoring: Review browser security logs and extension permissions to ensure no unauthorized processes are scraping URL history or address bar contents.
Compensating Controls: Use privacy-focused browser extensions that clear URL parameters automatically or utilize browser settings to disable persistent search bar history until the patch is applied.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
This vulnerability presents a clear risk to user privacy and data confidentiality. Organizations should prioritize the deployment of Firefox and Thunderbird updates to version 141 or 140.1 across all managed workstations to eliminate the risk of sensitive search query exposure.
More Mozilla CVEs
Sources
Originally found and disclosed by Sören Hentzschel, per the CVE Program record.