Clickjacking Vulnerability in Firefox Browser
CVE-2025-6434

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
24 June 2025

What is CVE-2025-6434?

A vulnerability in the Firefox browser allows an attacker to exploit the HTTPS-Only feature's exception page by omitting an anti-clickjacking delay. This flaw could enable malicious users to deceive individuals into permitting an exception, thereby forcing the browser to load a website over an insecure HTTP connection. This issue is present in all Firefox versions prior to 140, potentially compromising user privacy and security.

Affected Version(s)

Firefox < 140

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hafiizh & kang ali
.
CVE-2025-6434 : Clickjacking Vulnerability in Firefox Browser