cve/2025/CVE-2025-4083.md
2025-09-29 21:09:30 +02:00

1.1 KiB

CVE-2025-4083

Description

A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.

POC

Reference

No PoCs from references.

Github