PT-2025-18154 · Mozilla+4 · Thunderbird+5

Andrew Mccreight

·

Published

2025-04-29

·

Updated

2026-04-14

·

CVE-2025-4085

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 138 Thunderbird versions prior to 138
Description An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges.
Recommendations For Firefox versions prior to 138, update to version 138 or later. For Thunderbird versions prior to 138, update to version 138 or later.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-11100
ALT-PU-2025-14599
ALT-PU-2025-6353
ALT-PU-2025-6478
ALT-PU-2025-7695
ALT-PU-2025-7697
BDU:2025-11979
CVE-2025-4085
OPENSUSE-SU-2025:15045-1
USN-7991-1

Affected Products

Alt Linux
Astra Linux
Firefox
Linuxmint
Thunderbird
Ubuntu