CVE-2025-6427 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connection…
Critical CVSS: 9.1

CVE-2025-6427

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140 and Thunderbird < 140.
Vendor
Mozilla
Product
Firefox
CWE
CWE-693
Yayın Tarihi
2025-06-24 13:15:23
Güncelleme
2025-07-14 19:15:34
Source Identifier
security@mozilla.org
KEV Date Added
-

Kategoriler

Referanslar