CVE-2025-0237
Executive Summary
CVE-2025-0237: The WebChannel API in Firefox and Thunderbird failed to validate the sending principal, allowing an attacker to impersonate higher‑privilege contexts and potentially execute privileged code across processes. The flaw could enable privilege escalation attacks until mitigated in Firefox 134/ESR 128.6 and Thunderbird 134/ESR 128.6. No current CISA KEV listing.
Authoritative CVE Metadata - CVSS Base Score: 5.4 (MEDIUM) - Published: 2025-01-07T16:15:38.323 - Last Modified: 2026-10-05T15:10:00.590
Original Description: The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.
"To study and not think is a waste. To think and not study is dangerous."
— Confucius