Clickjacking Vulnerability in Firefox Browser
CVE-2025-6434
Currently unrated
What is CVE-2025-6434?
A vulnerability in the Firefox browser allows an attacker to exploit the HTTPS-Only feature's exception page by omitting an anti-clickjacking delay. This flaw could enable malicious users to deceive individuals into permitting an exception, thereby forcing the browser to load a website over an insecure HTTP connection. This issue is present in all Firefox versions prior to 140, potentially compromising user privacy and security.
Affected Version(s)
Firefox < 140