CVE-2025-4085: Potential information leakage and privilege escalation in UITour actor
An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-4085?
CVE-2025-4085 is classified as a high severity vulnerability due to its potential to leak sensitive information and escalate privileges.
How do I fix CVE-2025-4085?
To fix CVE-2025-4085, update Mozilla Firefox or Thunderbird to version 138 or later.
What types of software are affected by CVE-2025-4085?
CVE-2025-4085 affects Mozilla Firefox versions prior to 138 and Mozilla Thunderbird versions prior to 138.
What could an attacker exploit in CVE-2025-4085?
An attacker could exploit CVE-2025-4085 to leverage the privileged UITour actor for potentially leaking sensitive information.
What is the impact of CVE-2025-4085 on users?
The impact of CVE-2025-4085 on users may include unauthorized access to sensitive information and increased vulnerability to privilege escalation.