CVE-2025-6425: Mozilla Firefox

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.

Affected products

  • Mozilla Firefox: before 115.25.0 (fixed in 115.25.0); before 140.0 (fixed in 140.0); from 116.0, before 128.12.0 (fixed in 128.12.0)

Published 2025-06-24. Last modified 2026-10-05.