← CVE Tracker
9.1CRITICAL

CVE-2025-6427 — An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating…

Mozilla · Firefox · Published 24 Jun 2025 · Modified 30 Sept 2026

Description

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

References

What to do
  1. Check whether Firefox is in your asset inventory.
  2. Patch in the next maintenance window; prioritise internet-facing systems.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2025-6427