CVE-2025-4088 - "Firefox Storage Access API Cross-Site Request Forgery Vulnerability"
CVE ID : CVE-2025-4088
Published : April 29, 2025, 2:15 p.m. | 1 hour, 21 minutes ago
Description : A security vulnerability in Firefox allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability affects Firefox < 138 and Thunderbird < 138.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : April 29, 2025, 2:15 p.m. | 1 hour, 21 minutes ago
Description : A security vulnerability in Firefox allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability affects Firefox < 138 and Thunderbird < 138.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...