CVE-2025-9180

8.1

Mozilla · Firefox, Thunderbird

A same-origin policy bypass exists in the Graphics: Canvas2D component of Mozilla Firefox and Thunderbird, potentially allowing unauthorized data access.

Executive summary

A high-severity same-origin policy bypass in Mozilla Firefox and Thunderbird allows attackers to potentially access sensitive cross-origin data through malicious web content.

Vulnerability

This is a same-origin policy bypass vulnerability within the Graphics: Canvas2D component. The flaw can be triggered by an unauthenticated attacker via a victim interacting with malicious web content.

Business impact

The vulnerability carries a CVSS score of 8.1, indicating a high risk to data confidentiality and integrity. Successful exploitation could allow a remote attacker to bypass browser security boundaries to read sensitive information from other origins, potentially leading to the theft of session tokens, user credentials, or private browsing data.

Remediation

Immediate Action: Update all installations of Mozilla Firefox and Thunderbird to the latest versions, specifically version 142 or the corresponding ESR releases (115.27, 128.14, or 140.2) as specified by the vendor.

Proactive Monitoring: Monitor browser-based security logs for unusual cross-origin requests or anomalies in Canvas2D rendering operations.

Compensating Controls: Ensure that enterprise browser policies are configured to restrict script execution and limit access to untrusted domains where possible.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS severity and the potential for significant data exposure, organizations should prioritize the deployment of these patches across all endpoints. Users and IT administrators must ensure that automatic updates are enabled or that the manual update process is completed immediately to mitigate the risk of unauthorized data access.

More Mozilla CVEs

Sources

Originally found and disclosed by Tom Van Goethem, per the CVE Program record.