#VU111895 Protection Mechanism Failure in Mozilla Firefox and Firefox for Android - CVE-2025-6434
Published: June 24, 2025
Mozilla Firefox
Firefox for Android
Mozilla
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to the exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP.