CVE-2025-4083: Process isolation bypass using "javascript:" URI links in cross-origin frames
A process isolation vulnerability in Firefox stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape.
Other sources
A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape.
— Mozilla
A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document’s process instead of the intended frame, potentially enabling a sandbox escape.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 128.10 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 138 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 128.10 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 138 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.23 - Upgrade
Upgrade
Thunderbird ESRto a version that resolves this vulnerability.Fixed in 128.10
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-4083?
CVE-2025-4083 has been classified as a high severity vulnerability due to its potential to allow sandbox escape.
How do I fix CVE-2025-4083?
To mitigate CVE-2025-4083, users should update Firefox and Thunderbird to versions 138 or later and Firefox ESR to versions 128.10 or later.
What impact does CVE-2025-4083 have on users?
CVE-2025-4083 could enable malicious content to execute in the top-level document's process, compromising user security.
Which versions of Firefox are affected by CVE-2025-4083?
CVE-2025-4083 affects Firefox versions earlier than 138 and Firefox ESR versions earlier than 128.
Does CVE-2025-4083 affect Thunderbird?
Yes, CVE-2025-4083 affects Thunderbird versions prior to 138 and Thunderbird ESR versions prior to 128.10.