Resource Enumeration Flaw in Firefox WebCompat Extension
CVE-2025-6425
Currently unrated
What is CVE-2025-6425?
A security vulnerability has been identified in the WebCompat extension for Firefox that allows attackers to enumerate resources. This flaw could enable the retrieval of a persistent UUID that uniquely identifies the browser instance, which persists across both normal and private browsing modes, although it is not retained across different user profiles. This issue affects specific versions of Firefox, including those prior to 140, and specific releases of Firefox ESR (< 115.25 and < 128.12), potentially exposing users to privacy risks.
Affected Version(s)
Firefox < 140
Firefox ESR < 115.25
Firefox ESR < 128.12