URL Parsing Vulnerability Affecting Mozilla Firefox
CVE-2025-6429
Currently unrated
What is CVE-2025-6429?
A security flaw in Mozilla Firefox allows an incorrect parsing of URLs. Specifically, when a URL is within an 'embed' tag, Firefox could potentially rewrite it to point to the youtube.com domain. This misinterpretation of URLs may lead to a bypass of security measures designed to restrict which domains can be embedded on websites, opening avenues for potential exploitation. The vulnerability is present in versions of Firefox prior to 140 and Firefox ESR prior to 128.12.
Affected Version(s)
Firefox < 140
Firefox ESR < 128.12