Mozilla · Firefox · CVE-2025-1936
**Name of the Vulnerable Software and Affected Versions**
Firefox versions prior to 136
Firefox ESR versions prior to 128.8
**Description**
The issue allows jar: URLs to retrieve local file content packaged in a ZIP archive. When retrieving content from the archive, anything after a null character is ignored, but a fake extension after the null can be used to determine the content type. This could be exploited to hide code in a web extension disguised as a different file type, such as an image.
**Recommendations**
For Firefox versions prior to 136, update to version 136 or later.
For Firefox ESR versions prior to 128.8, update to version 128.8 or later.