An attacker with control over a content process could...
High severity
Unreviewed
Published
Apr 29, 2025
to the GitHub Advisory Database
•
Updated May 2, 2025
Description
Published by the National Vulnerability Database
Apr 29, 2025
Published to the GitHub Advisory Database
Apr 29, 2025
Last updated
May 2, 2025
An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. This vulnerability affects Firefox < 138 and Thunderbird < 138.
References