PT-2025-26730 · Mozilla+5 · Firefox+5
Simon
·
Published
2025-06-24
·
Updated
2026-02-02
·
CVE-2025-6433
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Firefox versions prior to 140
Description:
The issue arises when a user visits a webpage with an invalid TLS certificate and grants an exception. In this scenario, the webpage can provide a WebAuthn challenge that the user is prompted to complete, violating the WebAuthn specification that requires a secure transport established without errors.
Recommendations:
For Firefox versions prior to 140, update to version 140 or later to resolve the issue. As a temporary workaround, consider avoiding exceptions for invalid TLS certificates to minimize the risk of exploitation. Restrict access to WebAuthn challenges on webpages with invalid TLS certificates until the issue is resolved.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Firefox
Linuxmint
Suse
Ubuntu