Protection Mechanism Failure in Mozilla Firefox and Firefox for Android - CVE-2025-6434
Published: June 24, 2025
Mozilla Firefox
Firefox for Android
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to the exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP.