Description
A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
Published: 2025-02-04
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential privacy leakage through unintended display of private browsing data in normal windows
Action: Apply Patch
AI Analysis

Impact

A race condition in the browser’s handling of tab contexts can allow private browsing tabs to open inside a standard browsing window, exposing users’ confidential information. This flaw provides an unauthorized view into private content, constituting a privacy leak. The weakness falls under CWE‑362, indicating a timing flaw between concurrent operations.

Affected Systems

The flaw affects Mozilla Firefox and Mozilla Thunderbird browsers. Versions prior to Firefox 135 and Firefox ESR 128.7, and Thunderbird prior to Thunderbird 135 and Thunderbird ESR 128.7 are vulnerable. Red Hat Enterprise Linux packages that embed these browser components may also be affected if the bundled versions are out of date.

Risk and Exploitability

The CVSS score of 6.5 classifies the vulnerability as moderate. An EPSS score of less than 1% suggests a very low probability of exploitation in the wild, and the flaw is not currently listed in the CISA KEV catalog. The likely attack vector is local, requiring the attacker to have access to a user session or the browser process to trigger the race condition. Because the flaw depends on user activity and precise timing, the likelihood of successful exploitation remains low, but it should not be ignored because of the potential privacy impact.

Generated by OpenCVE AI on April 20, 2026 at 18:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox to version 135 or later, or to Firefox ESR 128.7 or later if using an extended‑support release.
  • Upgrade Mozilla Thunderbird to version 135 or later, or to Thunderbird ESR 128.7 or later if using an extended‑support release.
  • If an immediate update is not feasible, ensure that all X86_64 Red Hat Enterprise Linux package repositories are regularly checked for updated package lists that contain the latest browser versions, and apply those updates as soon as they are available.

Generated by OpenCVE AI on April 20, 2026 at 18:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4044-1 firefox-esr security update
Debian DLA Debian DLA DLA-4045-1 thunderbird security update
Debian DSA Debian DSA DSA-5858-1 firefox-esr security update
Debian DSA Debian DSA DSA-5860-1 thunderbird security update
EUVD EUVD EUVD-2025-1968 A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.
Ubuntu USN Ubuntu USN USN-7263-1 Firefox vulnerabilities
Ubuntu USN Ubuntu USN USN-7663-1 Thunderbird vulnerabilities
History

Mon, 13 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135. A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
Title firefox: thunderbird: Potential opening of private browsing tabs in normal browsing windows Potential opening of private browsing tabs in normal browsing windows

Mon, 03 Nov 2025 21:30:00 +0000

Type Values Removed Values Added
References

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00081}

epss

{'score': 0.00107}


Tue, 08 Apr 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla
Mozilla firefox
Mozilla thunderbird

Thu, 13 Feb 2025 01:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:8

Fri, 07 Feb 2025 14:30:00 +0000

Type Values Removed Values Added
Title firefox: thunderbird: Potential opening of private browsing tabs in normal browsing windows
First Time appeared Redhat
Redhat enterprise Linux
Redhat rhel Aus
Redhat rhel E4s
Redhat rhel Els
Redhat rhel Eus
Redhat rhel Tus
CPEs cpe:/a:redhat:enterprise_linux:9
cpe:/a:redhat:rhel_aus:8.2
cpe:/a:redhat:rhel_aus:8.4
cpe:/a:redhat:rhel_aus:8.6
cpe:/a:redhat:rhel_e4s:8.4
cpe:/a:redhat:rhel_e4s:8.6
cpe:/a:redhat:rhel_e4s:9.0
cpe:/a:redhat:rhel_eus:8.8
cpe:/a:redhat:rhel_eus:9.2
cpe:/a:redhat:rhel_eus:9.4
cpe:/a:redhat:rhel_tus:8.4
cpe:/a:redhat:rhel_tus:8.6
cpe:/o:redhat:rhel_els:7
Vendors & Products Redhat
Redhat enterprise Linux
Redhat rhel Aus
Redhat rhel E4s
Redhat rhel Els
Redhat rhel Eus
Redhat rhel Tus
References
Metrics threat_severity

None

threat_severity

Low


Tue, 04 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Feb 2025 14:15:00 +0000

Type Values Removed Values Added
Description A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.
References

Subscriptions

Mozilla Firefox Thunderbird
Redhat Enterprise Linux Rhel Aus Rhel E4s Rhel Els Rhel Eus Rhel Tus
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-04-13T14:25:18.645Z

Reserved: 2025-02-04T07:26:34.165Z

Link: CVE-2025-1013

cve-icon Vulnrichment

Updated: 2025-11-03T20:56:55.953Z

cve-icon NVD

Status : Modified

Published: 2025-02-04T14:15:32.123

Modified: 2026-04-13T15:16:49.900

Link: CVE-2025-1013

cve-icon Redhat

Severity : Low

Publid Date: 2025-02-04T13:58:54Z

Links: CVE-2025-1013 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-20T18:30:13Z

Weaknesses