CVE-2025-0237: WebChannel APIs susceptible to confused deputy attack
Last updated 9 January 2025
Other sources
The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-0237?
CVE-2025-0237 has been classified as a high-severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2025-0237?
To fix CVE-2025-0237, users should update their Firefox or Thunderbird applications to version 134 or higher, or Firefox ESR to 128.6.
Which software is affected by CVE-2025-0237?
CVE-2025-0237 affects versions of Firefox, Firefox ESR, and Thunderbird prior to the specified remedial versions.
What type of vulnerability is CVE-2025-0237?
CVE-2025-0237 is a privilege escalation vulnerability that exploits inadequate principal validation in the WebChannel API.
When was CVE-2025-0237 last updated?
CVE-2025-0237 was last updated on January 9, 2025.