URL Parsing Vulnerability Affecting Mozilla Firefox
CVE-2025-6429
6.5MEDIUM
What is CVE-2025-6429?
A security flaw in Mozilla Firefox allows an incorrect parsing of URLs. Specifically, when a URL is within an 'embed' tag, Firefox could potentially rewrite it to point to the youtube.com domain. This misinterpretation of URLs may lead to a bypass of security measures designed to restrict which domains can be embedded on websites, opening avenues for potential exploitation. The vulnerability is present in versions of Firefox prior to 140 and Firefox ESR prior to 128.12.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Firefox < 140
Firefox ESR < 128.12
Thunderbird < 140
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Masato Kinugawa