PT-2025-4126 · Mozilla+10 · Thunderbird+12

Maruf Bin Murtuza

·

Published

2025-02-04

·

Updated

2025-07-22

·

CVE-2025-1013

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 135 Firefox ESR versions prior to 128.7 Thunderbird versions prior to 128.7 Thunderbird versions prior to 135
Description A race condition could have led to private browsing tabs being opened in normal browsing windows, potentially resulting in a privacy leak.
Recommendations For Firefox versions prior to 135, update to version 135 or later to resolve the issue. For Firefox ESR versions prior to 128.7, update to version 128.7 or later to resolve the issue. For Thunderbird versions prior to 128.7, update to version 128.7 or later to resolve the issue. For Thunderbird versions prior to 135, update to version 135 or later to resolve the issue.

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:1066
ALSA-2025:1184
ALSA-2025:1283
ALSA-2025:1292
ALT-PU-2025-2842
ALT-PU-2025-3108
ALT-PU-2025-3294
ALT-PU-2025-4001
ALT-PU-2025-7695
ALT-PU-2025-7697
BDU:2025-02311
CESA-2025_1283
CESA-2025_1292
CVE-2025-1013
DLA-4044-1
DLA-4045-1
DSA-5858-1
DSA-5861-1
INFSA-2025_1066
INFSA-2025_1184
INFSA-2025_1283
INFSA-2025_1292
MGASA-2025-0045
MGASA-2025-0048
OESA-2025-1101
OESA-2025-1102
OESA-2025-1835
OPENSUSE-SU-2025:14727-1
OPENSUSE-SU-2025:14730-1
OPENSUSE-SU-2025:14731-1
OPENSUSE-SU-2025_0374-1
OPENSUSE-SU-2025_0405-1
RHSA-2025:1066
RHSA-2025:1132
RHSA-2025:1133
RHSA-2025:1135
RHSA-2025:1136
RHSA-2025:1137
RHSA-2025:1138
RHSA-2025:1139
RHSA-2025:1140
RHSA-2025:1184
RHSA-2025:1283
RHSA-2025:1292
RHSA-2025:1317
RHSA-2025:1318
RHSA-2025:1319
RHSA-2025:1339
RHSA-2025:1340
RHSA-2025:1341
RHSA-2025:1348
RHSA-2025_1066
RHSA-2025_1184
RHSA-2025_1283
RHSA-2025_1292
RLSA-2025:1283
RLSA-2025:1292
SUSE-SU-2025:0374-1
SUSE-SU-2025:0391-1
SUSE-SU-2025:0405-1
SUSE-SU-2025_0374-1
SUSE-SU-2025_0391-1
USN-7263-1
USN-7663-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Thunderbird
Ubuntu