CVE-2025-6434: Mozilla Firefox

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

Affected products

  • Mozilla Firefox: before 140.0 (fixed in 140.0)

Published 2025-06-24. Last modified 2026-09-30.