Description

The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability affects Firefox < 140 and Thunderbird < 140.

INFO

Published Date :

2025-06-24T12:28:04.375Z

Last Modified :

2025-10-30T16:13:36.740Z

Source :

mozilla
AFFECTED PRODUCTS

The following products are affected by CVE-2025-6434 vulnerability.

Vendors Products
Mozilla
  • Firefox

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact