When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not responding. This vulnerability was fixed in Firefox 140 and Thunderbird 140.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefox | Jul 5, 2025 | Jul 4, 2025 |
| Mfsa2025 51 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 140.0 | Jun 25, 2025 | Jun 24, 2025 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 140.0 | Jul 3, 2025 | Jun 24, 2025 |
| Suse | — | Upgrade xdg-desktop-portalUpgrade pipewire-modules-0_3Upgrade libpipewire-0_3-0Upgrade MozillaFirefox-translations-commonUpgrade pipewire-toolsUpgrade pipewire-spa-plugins-0_2Upgrade mozillafirefox-branding-upstreamUpgrade MozillaFirefox-develUpgrade gstreamer-plugin-pipewireUpgrade MozillaThunderbirdUpgrade pipewireUpgrade xdg-desktop-portal-langUpgrade MozillaFirefox-translations-otherUpgrade MozillaThunderbird-translations-commonUpgrade pipewire-modulesUpgrade MozillaFirefoxUpgrade pipewire-spa-toolsUpgrade mozillafirefox-branding-sleUpgrade pipewire-langUpgrade MozillaThunderbird-translations-otherUpgrade xdg-desktop-portal-devel | Jul 22, 2025 | Jun 24, 2025 |
| Ubuntu | — | Upgrade thunderbird | Jun 26, 2025 | Jun 24, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub