First published: Tue Apr 29 2025(Updated: )
A vulnerability existed in Firefox for Android where potentially sensitive library locations were logged via Logcat. This vulnerability affects Firefox < 138 and Thunderbird < 138.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <138 | |
Thunderbird | <138 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4090 has been classified as a moderate severity vulnerability due to the potential exposure of sensitive library locations.
To fix CVE-2025-4090, update Firefox for Android and Thunderbird to version 138 or later.
CVE-2025-4090 affects users of Firefox for Android versions earlier than 138 and Thunderbird versions earlier than 138.
CVE-2025-4090 could potentially log sensitive library locations, which may include paths to important system files.
As of now, there are no publicly available exploits for CVE-2025-4090, but the logging behavior could pose security risks.