CVE-2025-6427
Last modified
CVE-2025-6427 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability was fixed in Firefox 140 and Thunderbird 140.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 140.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-6427?
How severe is CVE-2025-6427?
How do I fix CVE-2025-6427?
Are you affected by CVE-2025-6427?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
