Mozilla Firefox and Thunderbird WebChannel API Privilege Escalation Vulnerability

Vulnerability

A vulnerability in the WebChannel API, used for inter-process communication, allowed for privilege escalation. The API accepted the sending principal without verification, potentially leading to unauthorized actions. This issue affects Firefox versions prior to 134, Firefox ESR versions prior to 128.6, Thunderbird versions prior to 134, and Thunderbird ESR versions prior to 128.6.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation.

Remediation

Users can upgrade to Firefox 134, Thunderbird 134, Firefox ESR 128.6, or Thunderbird ESR 128.6 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
5.0
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.