---
id: CVE-2025-0237
title: >-
  The WebChannel API, which is used to transport various information across
  processes, did not check the sending principal but rather accepted the
  principal being sent
summary: >-
  The WebChannel API, which is used to transport various information across
  processes, did not check the sending principal but rather accepted the
  principal being sent. This could have led to privilege escalation attacks.
  This vulnerabilit…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-863
vendor: mozilla
product: firefox
affected:
  - firefox < 128.6.0
  - firefox < 134.0
  - thunderbird < 128.6.0
  - 'thunderbird >= 129.0, < 134.0'
patched:
  - firefox 134.0
  - thunderbird 134.0
published: '2025-01-07'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T19:10:01.007'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-0237'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1915257'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-01/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-02/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-04/'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-05/'
    label: security@mozilla.org
  - url: 'https://lists.debian.org/debian-lts-announce/2025/01/msg00004.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00611
epssPercentile: 0.47256
ingestedAt: '2026-09-30T19:21:07.217Z'
---

## Overview

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

## Affected

- `firefox < 128.6.0`
- `firefox < 134.0`
- `thunderbird < 128.6.0`
- `thunderbird >= 129.0, < 134.0`

## Remediation

Upgrade past the affected range:

- `firefox 134.0`
- `thunderbird 134.0`
