WebAuthn Challenge Vulnerability in Mozilla Firefox
CVE-2025-6433
Currently unrated
What is CVE-2025-6433?
An issue exists in Mozilla Firefox where users visiting a webpage with an invalid TLS certificate may be prompted to complete a WebAuthn challenge. This occurs after users grant an exception for the invalid certificate, effectively allowing bypass of established security protocols as stated in the WebAuthn specification, which mandates a secure transport and unbroken connection during authentication procedures. Consequently, this vulnerability raises significant security concerns regarding improper handling of certificate errors and user authentication.
Affected Version(s)
Firefox < 140