URL Parsing Vulnerability Affecting Mozilla Firefox
CVE-2025-6429

6.5MEDIUM

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
24 June 2025

What is CVE-2025-6429?

A security flaw in Mozilla Firefox allows an incorrect parsing of URLs. Specifically, when a URL is within an 'embed' tag, Firefox could potentially rewrite it to point to the youtube.com domain. This misinterpretation of URLs may lead to a bypass of security measures designed to restrict which domains can be embedded on websites, opening avenues for potential exploitation. The vulnerability is present in versions of Firefox prior to 140 and Firefox ESR prior to 128.12.

Affected Version(s)

Firefox < 140

Firefox ESR < 128.12

Thunderbird < 140

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Masato Kinugawa
.