← CVE Tracker
8.1HIGH

CVE-2025-9180 — Same-origin policy bypass in the Graphics: Canvas2D component.

Mozilla · Firefox · Published 19 Aug 2025 · Modified 30 Sept 2026

Description

Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2.

References

What to do
  1. Check whether Firefox is in your asset inventory.
  2. Patch in the next maintenance window; prioritise internet-facing systems.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2025-9180