CVE-2025-3035

By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab would leak into the chat prompt. This vulnerability affects Firefox < 137.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*

History

15 Apr 2025, 12:55

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
First Time Mozilla firefox
Mozilla
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1952268 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1952268 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2025-20/ - () https://www.mozilla.org/security/advisories/mfsa2025-20/ - Vendor Advisory

10 Apr 2025, 21:15

Type Values Removed Values Added
CWE CWE-359
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
Summary
  • (es) Al usar el chatbot de IA en una pestaña y activarlo posteriormente en otra, el título del documento de la pestaña anterior se filtraba en el mensaje de chat. Esta vulnerabilidad afecta a Firefox (versión anterior a la 137).

01 Apr 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-01 13:15

Updated : 2025-04-15 12:55


NVD link : CVE-2025-3035

Mitre link : CVE-2025-3035

CVE.ORG link : CVE-2025-3035


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-359

Exposure of Private Personal Information to an Unauthorized Actor