Resource Enumeration Flaw in Firefox WebCompat Extension
CVE-2025-6425

Currently unrated

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
24 June 2025

What is CVE-2025-6425?

A security vulnerability has been identified in the WebCompat extension for Firefox that allows attackers to enumerate resources. This flaw could enable the retrieval of a persistent UUID that uniquely identifies the browser instance, which persists across both normal and private browsing modes, although it is not retained across different user profiles. This issue affects specific versions of Firefox, including those prior to 140, and specific releases of Firefox ESR (< 115.25 and < 128.12), potentially exposing users to privacy risks.

Affected Version(s)

Firefox < 140

Firefox ESR < 115.25

Firefox ESR < 128.12

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rob Wu
.
CVE-2025-6425 : Resource Enumeration Flaw in Firefox WebCompat Extension