CVE-2025-10536
Description
Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2025-10536 is an information disclosure vulnerability in Mozilla's Networking: Cache component, fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
Vulnerability
Overview
CVE-2025-10536 is an information disclosure flaw in the Networking: Cache component of Mozilla products. The vulnerability was reported by Ibuki Sato and has an associated Bugzilla entry (Bug 1981502) [3][4]. The official description indicates that this issue leads to the unintended exposure of sensitive data through the browser's networking cache.
Exploitation
Context
Successful exploitation of this vulnerability would allow an attacker to access potentially sensitive information stored or processed by the Networking Cache component. The attack surface is likely web-based, as the component is involved in caching HTTP responses and other network data. No specific authentication or network position requirements are detailed, but typical exploitation would require some form of user interaction or a malicious page to trigger the information disclosure [1][2].
Impact
Assessment
An attacker exploiting this vulnerability could gain access to cached data that may include sensitive information such as session tokens, personal data, or other confidential content. Mozilla's security advisory rates the overall impact for this specific CVE as "low", and the product-wide impact for the advisory is rated as "high" due to the presence of other more severe vulnerabilities [1][2]. The Thunderbird advisories note that these flaws cannot be exploited through email because scripting is disabled when reading mail, but they remain potential risks in browser or browser-like contexts [2][3].
Mitigation
Status
Mozilla has addressed this vulnerability in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3 [1][2][3][4]. Users are strongly advised to update their software to the latest available versions to protect against this and other security issues fixed in these releases.
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*+ 1 more
- cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*range: <143.0
- cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*range: <140.3.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.mozilla.org/security/advisories/mfsa2025-73/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2025-75/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2025-77/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2025-78/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingPermissions Required
- lists.debian.org/debian-lts-announce/2025/09/msg00020.htmlnvd
- lists.debian.org/debian-lts-announce/2025/09/msg00026.htmlnvd
News mentions
0No linked articles in our index yet.