CVE-2025-1019: Mozilla Firefox
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability was fixed in Firefox 135 and Thunderbird 135.
Affected products
- Mozilla Firefox: before 135.0 (fixed in 135.0)
- Mozilla Thunderbird: from 131.0, before 135.0 (fixed in 135.0)
Published 2025-02-04. Last modified 2026-10-05.