Critical severity9.8NVD Advisory· Published Jun 24, 2025· Updated Apr 13, 2026
CVE-2025-6433
CVE-2025-6433
Description
If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability was fixed in Firefox 140 and Thunderbird 140.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.mozilla.org/security/advisories/mfsa2025-51/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdPermissions Required
- www.mozilla.org/security/advisories/mfsa2025-54/nvd
News mentions
0No linked articles in our index yet.