Medium firefox Cross Origin

Overview

Medium
Severity
CVSS
No
Exploited ITW
Embargoed
Fix Status
Impactmoderate
DescriptionA security vulnerability in Firefox allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins.
ComponentCore
Bug ClassCross Origin
Tracker1953521
CISA KEVNot listed
CreditedChris P. Fredrickson
Disclosed2025-04-29

Fix not yet public

No public source fix for this bug has been identified on the main branch yet — it is embargoed or not yet disclosed. Root-cause analysis is withheld until the fix commit is available.
On This Page