Process isolation bypass using "javascript:" URI links in cross-origin
frames. (CVE-2025-4083)
Unsafe attribute access during XPath parsing. (CVE-2025-4087)
Memory safety bugs fixed in Firefox 138, Thunderbird 138, Firefox ESR
128.10, and Thunderbird 128.10. (CVE-2025-4091)
Memory safety bug fixed in Firefox ESR 128.10 and Thunderbird 128.10.
(CVE-2025-4093)
- https://bugs.mageia.org/show_bug.cgi?id=34233
- https://www.thunderbird.net/en-US/thunderbird/128.10.0esr/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-32/
- https://www.cve.org/CVERecord?id=CVE-2025-4083
- https://www.cve.org/CVERecord?id=CVE-2025-4087
- https://www.cve.org/CVERecord?id=CVE-2025-4091
- https://www.cve.org/CVERecord?id=CVE-2025-4093
- 9/core/thunderbird-128.10.0-1.mga9
- 9/core/thunderbird-l10n-128.10.0-1.mga9
Get the latest Linux and open source security news straight to your inbox.