Protection Mechanism Failure in Firefox for Android and Mozilla Firefox - CVE-2025-5271
Published: May 27, 2025
Vulnerability identifier: #VU109880
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-5271
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to Devtools ignores CSP headers when previewing content. A remote attacker can perform content injection attacks.
Affected software
Firefox for Android
Mozilla Firefox
Ubuntu
Mozilla Thunderbird
thunderbird (Ubuntu package)
Mozilla Firefox
Ubuntu
Mozilla Thunderbird
thunderbird (Ubuntu package)
How to mitigate CVE-2025-5271
Install updates from vendor's website.
Firefox for Android - update to 139.0
Mozilla Firefox - update to 139.0
Mozilla Thunderbird - update to 139.0
thunderbird (Ubuntu package) - update to 1:140.7.1+build1-0ubuntu0.22.04.1
Mozilla Firefox - update to 139.0
Mozilla Thunderbird - update to 139.0
thunderbird (Ubuntu package) - update to 1:140.7.1+build1-0ubuntu0.22.04.1