CVE-2025-4085High· 7.1▾ TwilightAn attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
firefox < 138.0thunderbird < 138.0Upgrade past the affected range:
firefox 138.0thunderbird 138.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100824High· 8.8Privilege escalation in the Places component
CVE-2026-100820High· 8.8Privilege escalation in the Address Bar component
CVE-2026-100807High· 8.8Privilege escalation in the DOM: Service Workers component
CVE-2026-100801High· 8.8Privilege escalation in the DLL Services component
CVE-2026-92015High· 8.8Privilege escalation in the WebExtensions component
CVE-2026-92017High· 8.8Privilege escalation in the DOM: Service Workers component