Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12686 | An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. This vulnerability affects Firefox < 138 and Thunderbird < 138. |
Ubuntu USN |
USN-7991-1 | Thunderbird vulnerabilities |
Mon, 13 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. This vulnerability affects Firefox < 138 and Thunderbird < 138. | An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. This vulnerability was fixed in Firefox 138 and Thunderbird 138. |
| Title | firefox: thunderbird: Potential information leakage and privilege escalation in UITour actor | Potential information leakage and privilege escalation in UITour actor |
Fri, 09 May 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla
Mozilla firefox Mozilla thunderbird |
|
| CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:* |
|
| Vendors & Products |
Mozilla
Mozilla firefox Mozilla thunderbird |
Fri, 02 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 May 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 01 May 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | firefox: thunderbird: Potential information leakage and privilege escalation in UITour actor | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 29 Apr 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. This vulnerability affects Firefox < 138 and Thunderbird < 138. | |
| References |
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2026-04-13T14:28:43.317Z
Reserved: 2025-04-29T13:13:38.767Z
Link: CVE-2025-4085
Updated: 2025-05-02T15:35:36.288Z
Status : Modified
Published: 2025-04-29T14:15:35.187
Modified: 2026-04-13T15:16:59.873
Link: CVE-2025-4085
OpenCVE Enrichment
Updated: 2026-04-20T20:45:16Z
EUVD
Ubuntu USN