CVE-2025-5263: Error handling for script execution was incorrectly isolated from web content
Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-5263?
CVE-2025-5263 is considered a high-severity vulnerability due to its potential to allow cross-origin leak attacks.
How do I fix CVE-2025-5263?
To fix CVE-2025-5263, update Mozilla Firefox to version 139 or Firefox ESR to version 128.11 or higher.
Which versions of Firefox are affected by CVE-2025-5263?
CVE-2025-5263 affects Firefox versions prior to 139 and Firefox ESR versions prior to 115.24 and 128.11.
Can CVE-2025-5263 lead to data breaches?
Yes, due to its ability to facilitate cross-origin leak attacks, CVE-2025-5263 can potentially lead to data breaches.
Is there a workaround for CVE-2025-5263?
There are no known workarounds for CVE-2025-5263; the recommended action is to update to the latest version.