Mozilla Firefox Same-Origin Policy Bypass Vulnerability in Notifications Component

Vulnerability

A same-origin policy bypass vulnerability has been identified in the DOM Notifications component of Mozilla Firefox. This issue affects Firefox versions prior to 145 and Firefox ESR versions prior to 140.5. The vulnerability allows for unauthorized access or manipulation of notifications across different origins, potentially leading to privacy concerns or exploitation of notification-based features.

Impact

Exploitation of this vulnerability allows for a same-origin policy bypass, enabling cross-origin interactions with the Notifications component, which could be misused to access or manipulate notification data from different origins.

Remediation

Users can upgrade to Firefox 145 or Firefox ESR 140.5 to address this vulnerability.

Added: Nov 11, 2025, 4:29 PM
Updated: Nov 11, 2025, 4:29 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.4
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.