A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.
2025-03-04T14:15:38.390
2025-04-03T13:30:01.180
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mozilla | firefox | < 128.8.0 | Yes |
| Application | mozilla | firefox | < 136.0 | Yes |
| Application | mozilla | thunderbird | < 128.8.0 | Yes |
| Application | mozilla | thunderbird | < 136.0 | Yes |