{"id":"CVE-2024-7525","details":"It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox \u003c 129, Firefox ESR \u003c 115.14, Firefox ESR \u003c 128.1, Thunderbird \u003c 128.1, and Thunderbird \u003c 115.14.","modified":"2026-07-17T21:03:07.784577909Z","published":"2024-08-06T13:15:57.420Z","related":["ALSA-2024:5322","ALSA-2024:5391","ALSA-2024:5392","ALSA-2024:5402","SUSE-SU-2024:2876-1","SUSE-SU-2024:3003-1","SUSE-SU-2024:3112-1","SUSE-SU-2024:3507-1","openSUSE-SU-2024:14250-1","openSUSE-SU-2024:14260-1","openSUSE-SU-2024:14572-1"],"references":[{"type":"ADVISORY","url":"https://www.mozilla.org/security/advisories/mfsa2024-35/"},{"type":"ADVISORY","url":"https://www.mozilla.org/security/advisories/mfsa2024-37/"},{"type":"ADVISORY","url":"https://www.mozilla.org/security/advisories/mfsa2024-38/"},{"type":"ADVISORY","url":"https://www.mozilla.org/security/advisories/mfsa2024-33/"},{"type":"ADVISORY","url":"https://www.mozilla.org/security/advisories/mfsa2024-34/"},{"type":"REPORT","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1909298"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"129.0"}]},{"events":[{"introduced":"0"},{"fixed":"115.14.0"}]},{"events":[{"introduced":"0"},{"last_affected":"128.0"}]},{"events":[{"introduced":"0"},{"fixed":"115.14.0"}]},{"events":[{"introduced":"0"},{"last_affected":"128.0.1"}]}],"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-7525.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"}]}