CVE-2025-3035
⚪ Do wiadomości
Wyciekanie tytułu dokumentu w Firefox umożliwia ujawnienie informacji o aktywnych kartach.
CVSS
5.3
EPSS
0.3%
Exploit
none
Vendor
mozilla
Opis źródłowy (NVD)
By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab would leak into the chat prompt. This vulnerability was fixed in Firefox 137.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2025-04-01 13:15:41 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 19:10:01 UTC |
Referencje
- https://bugzilla.mozilla.org/show_bug.cgi?id=1952268 ([email protected]) [Permissions Required]
- https://www.mozilla.org/security/advisories/mfsa2025-20/ ([email protected]) [Vendor Advisory]