CVE-2025-4090: Leaked library paths in Thunderbird for Android
A vulnerability existed in Firefox for Android where potentially sensitive library locations were logged via Logcat.
Other sources
A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-4090?
CVE-2025-4090 has been classified as a moderate severity vulnerability due to the potential exposure of sensitive library locations.
How do I fix CVE-2025-4090?
To fix CVE-2025-4090, update Firefox for Android and Thunderbird to version 138 or later.
Who is affected by CVE-2025-4090?
CVE-2025-4090 affects users of Firefox for Android versions earlier than 138 and Thunderbird versions earlier than 138.
What types of data are exposed due to CVE-2025-4090?
CVE-2025-4090 could potentially log sensitive library locations, which may include paths to important system files.
Is there a known exploit for CVE-2025-4090?
As of now, there are no publicly available exploits for CVE-2025-4090, but the logging behavior could pose security risks.