Same-origin policy bypass in the DOM: Notifications...
High severity
Unreviewed
Published
Nov 11, 2025
to the GitHub Advisory Database
•
Updated Nov 19, 2025
Description
Published by the National Vulnerability Database
Nov 11, 2025
Published to the GitHub Advisory Database
Nov 11, 2025
Last updated
Nov 19, 2025
Same-origin policy bypass in the DOM: Notifications component. This vulnerability affects Firefox < 145 and Firefox ESR < 140.5.
References