Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2025:02339-1 — mozillafirefox (CVE-2025-6424 +12 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for MozillaFirefox, MozillaFirefox-branding-SLE

This update for MozillaFirefox, MozillaFirefox-branding-SLE fixes the following issues:

This is the Firefox Extended Support Release 140.0esr ESR

Major changes:

General:

  • Reader View now has an enhanced Text and Layout menu with

new options for character spacing, word spacing, and text

alignment. These changes offer a more accessible reading

experience.

  • Reader View now has a Theme menu with additional Contrast

and Gray options. You can also select custom colors for text,

background, and links from the Custom tab.

  • Firefox will now offer to temporarily remember when users

grant permissions to sites (e.g. geolocation). Temporary

permissions will be removed either after one hour or when the

tab is closed.

  • Firefox now includes safeguards to prevent sites from

abusing the history API by generating excessive history

entries, which can make navigating with the back and forward

buttons difficult by cluttering the history. This

intervention ensures that such entries, unless interacted

with by the user, are skipped when using the back and forward

buttons.

  • Firefox now identifies all links in PDFs and turns them

into hyperlinks.

  • You can now copy links from background tabs using the

tabstrip context menu on macOS and Linux.

  • Users on macOS and Linux are now given the option to close

only the current tab if the Quit keyboard shortcut is used

while multiple tabs are open in the window. (bmo#None)

Sidebar and Tabs:

  • You can now enable the updated Firefox sidebar in Settings

> General > Browser Layout to quickly access multiple tools

in one click, without leaving your main view. Sidebar tools

include an AI chatbot of your choice, bookmarks, history, and

tabs from devices you sync with your Mozilla account.

  • Keep a lot of tabs open? Try our new vertical tabs layout

to quickly scan your list of tabs. With vertical tabs, your

open and pinned tabs appear in the sidebar instead of along

the top of the browser. To turn on vertical tabs, right-click

on the toolbar near the top of the browser and select Turn on

Vertical Tabs. If you’ve enabled the updated sidebar, you can

also go to Customize sidebar and check Vertical tabs. Early

testers report feeling more organized after using vertical

tabs for a few days.

  • Stay productive and organized with less effort by grouping

related tabs together. One simple way to create a group is to

drag a tab onto another, pause until you see a highlight,

then drop to create the group. Tab groups can be named,

color-coded, and are always saved. You can close a group and

reopen it later.

  • A tab preview is now displayed when hovering the mouse over

background tabs, making it easier to locate the desired tab

without needing to switch tabs.

  • The sidebar to view tabs from other devices can now be

opened via the Tab overview menu.

Security & Privacy:

  • HTTPS is replacing HTTP as the default protocol in the

address bar on non-local sites. If a site is not available

via HTTPS, Firefox will fall back to HTTP.

  • Firefox now blocks third-party cookie access when Enhanced

Tracking Protection's Strict mode is enabled.

  • Firefox now has a new anti-tracking feature, Bounce

Tracking Protection, which is now available in Enhanced

Tracking Protection's 'Strict' mode. This feature detects

bounce trackers based on their redirect behavior and

periodically purges their cookies and site data to block

tracking.

  • Firefox now enforces certificate transparency, requiring

web servers to provide sufficient proof that their

certificates were publicly disclosed before they will be

trusted. This only affects servers using certificates issued

by a certificate authority in Mozilla's Root CA Program.

  • Smartblock Embeds allows users to selectively unblock

certain social media embeds that are blocked in ETP Strict

and Private Browsing modes. Currently, support is limited to

a few embed types, with more to be added in future updates.

  • Firefox now upgrades page loads to HTTPS by default and

gracefully falls back to HTTP if the secure connection fails.

This behavior is known as HTTPS-First.

  • The 'Copy Without Site Tracking' menu item was renamed to

'Copy Clean Link' to help clarify expectations around what

the feature does. 'Copy Clean Link' is a list based approach

to remove - known tracking parameters from links. This option

can also now be used on plain text links.

  • The Clear browsing data and cookies dialog now allows

clearing saved form info separately from browsing history.

Translations:

  • Firefox now allows translating selected text portions to

different languages after a full-page translation.

  • Full-Page Translations are now available within Firefox

ex

Affected software

SUSE-SU-2025:02339-1 is recorded against 2 packages.

  • mozillafirefox (fixed in 140.0-112.270.2)
  • mozillafirefox-branding-sle (fixed in 140-35.19.5)

Timeline and source

Published on 17 July 2025 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-07-17
Updated 2026-08-20
Modified 2026-03-23
Fix URL N/A

Affected Packages

Software From version Fixed in
mozillafirefox 140.0-112.270.2
mozillafirefox-branding-sle 140-35.19.5

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2025:02339-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:02339-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.