Cross-site request forgery in Firefox for Android and Mozilla Firefox - CVE-2025-4088

 

Cross-site request forgery in Firefox for Android and Mozilla Firefox - CVE-2025-4088

Published: April 29, 2025


Vulnerability identifier: #VU108053
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-4088
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform cross-site request forgery attacks.

The vulnerability exists due to insufficient validation of the HTTP request origin. A malicious website can use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API.


Affected software

Firefox for Android
Mozilla Firefox
Ubuntu
Mozilla Thunderbird
thunderbird (Ubuntu package)

How to mitigate CVE-2025-4088

Install updates from vendor's website.

Firefox for Android - update to 138.0
Mozilla Firefox - update to 138.0
Mozilla Thunderbird - update to 138.0
thunderbird (Ubuntu package) - update to 1:140.7.1+build1-0ubuntu0.22.04.1

External References

Related Security Bulletins