#VU111890 Protection Mechanism Failure in Mozilla Firefox and Firefox for Android - CVE-2025-6427
Published: June 24, 2025
Mozilla Firefox
Firefox for Android
Mozilla
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient implementation of security measures. An attacker is able to bypass the connect-src directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools.