CVE-2025-1018: Mozilla Firefox

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This vulnerability was fixed in Firefox 135 and Thunderbird 135.

Affected products

  • Mozilla Firefox: before 135.0 (fixed in 135.0)
  • Mozilla Thunderbird: from 131.0, before 135.0 (fixed in 135.0)

Published 2025-02-04. Last modified 2026-10-05.