CVE-2025-6434
The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability affects Firefox < 140 and Thunderbird < 140.
Vendor
Product
CWE
Yayın Tarihi
2025-06-24 13:15:24
Güncelleme
2025-07-14 19:15:35
Source Identifier
security@mozilla.org
KEV Date Added
-