CVE-2025-6432 — Sensitive Information Exposure in Mozilla Firefox
Severity
8.6HIGHNVD
EPSS
0.1%
top 70.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 24
Latest updateFeb 2
Description
When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not responding. This vulnerability was fixed in Firefox 140 and Thunderbird 140.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:LExploitability: 3.9 | Impact: 4.7
Affected Packages2 packages
🔴Vulnerability Details
3GHSA▶
GHSA-43h2-r954-f6w6: When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not↗2025-06-26
OSV▶
CVE-2025-6432: When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not↗2025-06-24
📋Vendor Advisories
5Debian▶
CVE-2025-6432: firefox - When Multi-Account Containers was enabled, DNS requests could have bypassed a SO...↗2025