← CVE Tracker
8.1HIGH
CVE-2025-9180 — Same-origin policy bypass in the Graphics: Canvas2D component.
Mozilla · Firefox · Published 19 Aug 2025 · Modified 30 Sept 2026
Description
Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2.
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1979782
- https://www.mozilla.org/security/advisories/mfsa2025-64/
- https://www.mozilla.org/security/advisories/mfsa2025-65/
- https://www.mozilla.org/security/advisories/mfsa2025-66/
- https://www.mozilla.org/security/advisories/mfsa2025-67/
- https://www.mozilla.org/security/advisories/mfsa2025-70/
- https://www.mozilla.org/security/advisories/mfsa2025-71/
- https://www.mozilla.org/security/advisories/mfsa2025-72/
- https://lists.debian.org/debian-lts-announce/2025/08/msg00016.html
- https://lists.debian.org/debian-lts-announce/2025/08/msg00018.html
What to do
- Check whether Firefox is in your asset inventory.
- Patch in the next maintenance window; prioritise internet-facing systems.
- Record the decision in your risk register for audit evidence.
Share
Link: adminadda.com/cve/CVE-2025-9180