Mozilla Firefox and Firefox ESR Cross-Origin Resource Status Leak Vulnerability

Vulnerability

A vulnerability exists in Firefox versions prior to 139 and Firefox ESR versions prior to 128.11, where script elements loading cross-origin resources could generate load and error events that leaked information. This leakage could be exploited to perform XS-Leaks attacks.

Impact

Exploitation of this vulnerability could lead to cross-site leakage attacks, allowing an attacker to gather information about the user's interactions with other sites.

Remediation

Users can upgrade to Firefox 139 or Firefox ESR 128.11 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.