CVE-2025-9180 | Mozilla Thunderbird up to 141 Canvas2D cross-domain policy (Nessus ID 253512 / WID-SEC-2025-1866)
A vulnerability was found in Mozilla Thunderbird up to 141. It has been declared as problematic. This affects an unknown part of the component Canvas2D. The manipulation leads to permissive cross-domain policy with untrusted domains.
This vulnerability is listed as CVE-2025-9180. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.