CVE-2025-1019: Mozilla Firefox

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability was fixed in Firefox 135 and Thunderbird 135.

Affected products

  • Mozilla Firefox: before 135.0 (fixed in 135.0)
  • Mozilla Thunderbird: from 131.0, before 135.0 (fixed in 135.0)

Published 2025-02-04. Last modified 2026-10-05.