#VU111886 Information disclosure in Mozilla products - CVE-2025-6425
Published: June 24, 2025
Firefox ESR
Mozilla Firefox
Firefox for Android
Mozilla
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the WebCompat extension shipped with Firefox allows to enumerate resources and obtain a persistent UUID that identifies the browser, and persists between containers and normal/private browsing mode, but not profiles.