CVE-2025-6425
24.06.2025, 13:15
An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 < 115.25.0 |
mozilla | firefox | 𝑥 < 140.0 |
mozilla | firefox | 116.0 ≤ 𝑥 < 128.12.0 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||||
firefox-esr |
| ||||||||||||||
thunderbird |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||
thunderbird |
| ||||||||||||
mozjs38 |
| ||||||||||||
mozjs52 |
| ||||||||||||
mozjs68 |
| ||||||||||||
mozjs78 |
| ||||||||||||
mozjs91 |
| ||||||||||||
mozjs102 |
| ||||||||||||
mozjs115 |
|
Common Weakness Enumeration
References