CVE-2025-9180: Same-origin policy bypass in the Graphics: Canvas2D component
'Same-origin policy bypass in the Graphics: Canvas2D component.' This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.
Other sources
Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2.
— MITRE
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-9180?
CVE-2025-9180 has a moderate severity level due to its ability to bypass the same-origin policy in affected applications.
How do I fix CVE-2025-9180?
To mitigate CVE-2025-9180, users should update their Firefox or Thunderbird applications to the latest version that addresses this vulnerability.
Which versions are affected by CVE-2025-9180?
CVE-2025-9180 affects Firefox versions prior to 142, Firefox ESR prior to 115.27, 128.14, and 140.2, as well as Thunderbird versions prior to 142, 128.14, and 140.2.
What components are impacted by CVE-2025-9180?
CVE-2025-9180 impacts the Graphics: Canvas2D component within the affected versions of Firefox and Thunderbird.
Can CVE-2025-9180 lead to data leakage?
Yes, due to the same-origin policy bypass, CVE-2025-9180 can potentially lead to unauthorized access to sensitive data across different origins.