Back to search
CVE-2025-6434
Published: Jun 24, 2025
Modified: Apr 13, 2026
PUBLISHED
Description
The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability was fixed in Firefox 140 and Thunderbird 140.
| Vendor | Product | Versions |
|---|---|---|
Mozilla | Firefox | unaffected 140 - <= * |
Mozilla | Thunderbird | unaffected 140 - <= * |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now