CVE-2025-4085EPSS p20.7%
CVE-2025-4085CVE-2025-4085
mozilla / firefox
Description
An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
Scoring
| CVSS | 7.1 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
| EPSS | 0.30% probability of exploitation · percentile 20.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |