Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading as legitimate content. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, Thunderbird < 128.5, and Thunderbird < 115.18.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbirdUpgrade firefoxUpgrade firefox-x11 | Dec 6, 2024 | Nov 26, 2024 |
| Alpine Linux | — | Upgrade firefox-esrUpgrade thunderbirdUpgrade firefox | Aug 8, 2025 | Nov 26, 2024 |
| Amazon Linux Ami 2 | — | Upgrade firefox-debuginfoUpgrade firefox | Dec 20, 2024 | Nov 26, 2024 |
| Debian | — | Upgrade thunderbirdUpgrade firefox-esr | Dec 2, 2024 | Nov 26, 2024 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox-bin.Upgrade dev-lang/spidermonkey.Upgrade www-client/firefox.Upgrade mail-client/thunderbird. | Jan 24, 2025 | Nov 26, 2024 |
| Mfsa2024 63 | — | Upgrade to Mozilla Firefox version 133.0 | Nov 27, 2024 | Nov 26, 2024 |
| Mfsa2024 64 | — | Upgrade to Mozilla Firefox ESR version 128.5 | Nov 27, 2024 | Nov 26, 2024 |
| Mfsa2024 65 | — | Upgrade to Mozilla Firefox ESR version 115.18 | Nov 27, 2024 | Nov 26, 2024 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 115.18 | Nov 27, 2024 | Nov 26, 2024 |
| Oracle_linux | — | Upgrade firefox-x11Upgrade thunderbirdUpgrade firefox | Dec 3, 2024 | Nov 26, 2024 |
| Redhat_linux | — | Upgrade qemu-kvm-device-usb-redirect-debuginfoNo solution existsUpgrade qemu-kvm-ui-opengl-debuginfoUpgrade qemu-kvm-device-display-virtio-gpu-pci-debuginfoUpgrade firefox-x11Upgrade qemu-kvmUpgrade qemu-kvm-device-display-virtio-vgaUpgrade qemu-kvm-core-debuginfoUpgrade qemu-kvm-ui-openglUpgrade qemu-kvm-audio-pa-debuginfoUpgrade qemu-img-debuginfoUpgrade qemu-kvm-device-usb-redirectUpgrade firefox-debugsourceUpgrade qemu-imgUpgrade qemu-kvm-ui-egl-headlessUpgrade thunderbirdUpgrade thunderbird-debuginfoUpgrade qemu-kvm-device-usb-hostUpgrade qemu-kvm-commonUpgrade qemu-kvm-toolsUpgrade qemu-kvm-block-rbdUpgrade qemu-kvm-common-debuginfoUpgrade qemu-kvm-coreUpgrade qemu-kvm-device-display-virtio-gpu-ccw-debuginfoUpgrade firefoxUpgrade qemu-kvm-tools-debuginfoUpgrade qemu-kvm-audio-paUpgrade qemu-kvm-debugsourceUpgrade qemu-kvm-docsUpgrade qemu-kvm-block-blkio-debuginfoUpgrade qemu-kvm-block-curlUpgrade qemu-kvm-block-rbd-debuginfoUpgrade qemu-kvm-device-display-virtio-gpu-debuginfoUpgrade qemu-kvm-device-display-virtio-gpu-pciUpgrade qemu-kvm-block-blkioUpgrade qemu-kvm-audio-dbus-debuginfoUpgrade qemu-kvm-block-curl-debuginfoUpgrade qemu-pr-helperUpgrade qemu-guest-agent-debuginfoUpgrade qemu-kvm-device-display-virtio-vga-debuginfoUpgrade qemu-guest-agentUpgrade qemu-kvm-ui-egl-headless-debuginfoUpgrade qemu-kvm-ui-dbus-debuginfoUpgrade qemu-kvm-device-display-virtio-gpu-ccwUpgrade firefox-debuginfoUpgrade thunderbird-debugsourceUpgrade qemu-kvm-tests-debuginfoUpgrade qemu-kvm-device-usb-host-debuginfoUpgrade qemu-pr-helper-debuginfoUpgrade qemu-kvm-device-display-virtio-gpu | Feb 10, 2025 | Nov 26, 2024 |
| Rocky_linux | — | Upgrade qemu-imgUpgrade qemu-kvm-common-debuginfoUpgrade qemu-kvm-device-display-virtio-gpu-pciUpgrade qemu-kvm-block-blkioUpgrade qemu-kvm-tools-debuginfoUpgrade qemu-kvm-audio-pa-debuginfoUpgrade firefoxUpgrade qemu-kvm-device-usb-hostUpgrade qemu-kvm-debugsourceUpgrade qemu-kvm-device-usb-redirect-debuginfoUpgrade thunderbirdUpgrade qemu-kvm-block-blkio-debuginfoUpgrade qemu-kvm-commonUpgrade qemu-kvm-docsUpgrade qemu-kvm-block-rbd-debuginfoUpgrade qemu-kvm-core-debuginfoUpgrade qemu-pr-helper-debuginfoUpgrade qemu-kvm-ui-openglUpgrade qemu-kvm-device-display-virtio-gpu-pci-debuginfoUpgrade qemu-kvm-toolsUpgrade qemu-kvmUpgrade qemu-kvm-device-display-virtio-gpuUpgrade qemu-kvm-coreUpgrade qemu-kvm-device-display-virtio-vga-debuginfoUpgrade firefox-debuginfoUpgrade qemu-kvm-block-rbdUpgrade qemu-kvm-block-curlUpgrade qemu-kvm-ui-opengl-debuginfoUpgrade thunderbird-debugsourceUpgrade qemu-guest-agentUpgrade qemu-img-debuginfoUpgrade qemu-kvm-device-display-virtio-gpu-ccw-debuginfoUpgrade qemu-kvm-audio-paUpgrade qemu-kvm-ui-egl-headless-debuginfoUpgrade qemu-kvm-ui-egl-headlessUpgrade qemu-kvm-block-curl-debuginfoUpgrade qemu-kvm-device-display-virtio-vgaUpgrade qemu-guest-agent-debuginfoUpgrade qemu-kvm-device-usb-host-debuginfoUpgrade thunderbird-debuginfoUpgrade qemu-kvm-device-display-virtio-gpu-ccwUpgrade qemu-pr-helperUpgrade firefox-debugsourceUpgrade qemu-kvm-device-usb-redirectUpgrade qemu-kvm-device-display-virtio-gpu-debuginfo | Feb 5, 2026 | Dec 19, 2024 |
| Suse | — | Upgrade mozjs128-develUpgrade libmozjs-128-0Upgrade mozillathunderbird-translations-otherUpgrade mozillathunderbirdUpgrade mozillafirefox-translations-otherUpgrade mozillafirefox-develUpgrade mozillafirefox-translations-commonUpgrade mozillathunderbird-translations-commonUpgrade mozjs128Upgrade mozillafirefoxUpgrade mozillafirefox-branding-upstream | Jan 3, 2025 | Nov 26, 2024 |
| Ubuntu | — | Upgrade firefoxUpgrade thunderbird | Dec 4, 2024 | Nov 26, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub