#VU116993 Permissions, Privileges, and Access Controls in Mozilla products - CVE-2025-11711
Published: October 14, 2025
Firefox ESR
Mozilla Firefox
Firefox for Android
Mozilla
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to application does not properly impose security restrictions, which allows an malicious web application to modify JavaScript Object properties that were supposed to be non-writable. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code on the system.