CVE-2025-6432
BaseFortify
Publication date: 2025-06-24
Last updated on: 2026-04-13
Assigner: Mozilla Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mozilla | firefox | From 60.9.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability occurs when the Multi-Account Containers feature is enabled in Firefox versions prior to 140. In such cases, DNS requests could bypass a configured SOCKS proxy if the domain name was invalid or if the SOCKS proxy was not responding, potentially exposing DNS traffic that was intended to be routed through the proxy.
How can this vulnerability impact me? :
The vulnerability can lead to DNS requests bypassing the SOCKS proxy, which may expose user browsing activity or DNS queries to unintended parties. This could reduce privacy and security by leaking information that was expected to be protected by the proxy.