CVE-2025-4088 | Mozilla Thunderbird up to 137.x Storage Access API access control (WID-SEC-2025-1850)
A vulnerability, which was classified as critical, has been found in Mozilla Thunderbird up to 137.x. Affected is an unknown function of the component Storage Access API. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2025-4088. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.