First published: Tue Apr 01 2025(Updated: )
By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab would leak into the chat prompt.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <137 | 137 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-3035 has been assessed as a potential information disclosure vulnerability, which can lead to sensitive document titles being leaked.
To mitigate CVE-2025-3035, update Firefox to version 138 or later, where the vulnerability has been addressed.
CVE-2025-3035 specifically affects Mozilla Firefox versions up to 137.
The primary risk of CVE-2025-3035 is that it may unintentionally expose document titles to other users if the chat functionality is misused.
CVE-2025-3035 does not appear to be exploitable remotely, as it requires user interaction within the same browsing session.