PT-2025-26730 · Mozilla+5 · Firefox+5

Simon

·

Published

2025-06-24

·

Updated

2026-02-02

·

CVE-2025-6433

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Firefox versions prior to 140
Description: The issue arises when a user visits a webpage with an invalid TLS certificate and grants an exception. In this scenario, the webpage can provide a WebAuthn challenge that the user is prompted to complete, violating the WebAuthn specification that requires a secure transport established without errors.
Recommendations: For Firefox versions prior to 140, update to version 140 or later to resolve the issue. As a temporary workaround, consider avoiding exceptions for invalid TLS certificates to minimize the risk of exploitation. Restrict access to WebAuthn challenges on webpages with invalid TLS certificates until the issue is resolved.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-11100
ALT-PU-2025-11495
ALT-PU-2025-11497
ALT-PU-2025-14599
ALT-PU-2025-8725
ALT-PU-2025-9988
BDU:2025-07649
CVE-2025-6433
OPENSUSE-SU-2025:15325-1
OPENSUSE-SU-2025:15371-1
OPENSUSE-SU-2025:15383-1
SUSE-SU-2025:02339-1
SUSE-SU-2025:02529-1
SUSE-SU-2025:02546-1
SUSE-SU-2025_02339-1
SUSE-SU-2025_02529-1
USN-7991-1

Affected Products

Alt Linux
Astra Linux
Firefox
Linuxmint
Suse
Ubuntu