PT-2025-26729 · Mozilla+5 · Firefox+5
Albert
·
Published
2025-06-24
·
Updated
2026-02-02
·
CVE-2025-6432
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:N/C:C/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Firefox versions prior to 140
Description:
The issue occurs when Multi-Account Containers is enabled, allowing DNS requests to bypass a SOCKS proxy under certain conditions, such as when the domain name is invalid or the SOCKS proxy is not responding.
Recommendations:
For versions prior to 140, update to version 140 or later to resolve the issue. As a temporary workaround, consider disabling Multi-Account Containers until the update is applied. Restrict access to SOCKS proxies to minimize the risk of exploitation. Avoid using invalid domain names in SOCKS proxy configurations until the issue is resolved.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Firefox
Linuxmint
Suse
Ubuntu