CVE-2025-10529: Same-origin policy bypass in the Layout component
Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
Other sources
This vulnerability affects Firefox < 143 and Firefox ESR < 140.3.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-10529?
CVE-2025-10529 has been classified as a critical vulnerability affecting certain versions of Firefox.
How do I fix CVE-2025-10529?
To remediate CVE-2025-10529, update Firefox to version 143 or Firefox ESR to version 140.3 or later.
What versions of Firefox are affected by CVE-2025-10529?
CVE-2025-10529 affects Firefox versions prior to 143 and Firefox ESR versions prior to 140.3.
What impact does CVE-2025-10529 have on users?
CVE-2025-10529 could potentially allow remote code execution, putting users at significant risk.
Is there a workaround for CVE-2025-10529?
Currently, the best mitigation for CVE-2025-10529 is to immediately update to the latest version of Firefox or Firefox ESR.