Description

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140 and Thunderbird < 140.

INFO

Published Date :

2025-06-24T12:28:01.317Z

Last Modified :

2025-10-30T16:13:22.016Z

Source :

mozilla
AFFECTED PRODUCTS

The following products are affected by CVE-2025-6427 vulnerability.

Vendors Products
Mozilla
  • Firefox

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact