CVE-2025-4088: Cross-site request forgery via storage access API redirects
A security vulnerability in Firefox allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins.
Other sources
A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-4088?
CVE-2025-4088 has been rated as a high severity vulnerability due to its potential to facilitate Cross-Site Request Forgery attacks.
How do I fix CVE-2025-4088?
To fix CVE-2025-4088, upgrade to Firefox or Thunderbird version 138 or later.
What products are affected by CVE-2025-4088?
CVE-2025-4088 affects Firefox and Thunderbird versions prior to 138.
Can CVE-2025-4088 be exploited remotely?
Yes, CVE-2025-4088 can be exploited remotely as malicious sites can use redirects to launch attacks.
What are the risks associated with CVE-2025-4088?
The risks associated with CVE-2025-4088 include unauthorized access to user credentials and the potential for data breaches via Cross-Site Request Forgery.