CVE-2025-6425

MEDIUM

Firefox < 115.25.0, 115.25-115.*, 128.12-128.*, >=140 - Exposure of Sensitive Information via WebCompat Extension

Title source: llm
STIX 2.1

Description

An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.

Scores

CVSS v3 4.3
EPSS 0.0041
EPSS Percentile 61.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (7)
mozilla/firefox < 115.25.0
mozilla/firefox < 140.0
Mozilla/Firefox 115.25 - 115.*
Mozilla/Firefox 128.12 - 128.*
Mozilla/Firefox 140
Mozilla/Thunderbird 128.12 - 128.*
Mozilla/Thunderbird 140
Published Jun 24, 2025
Tracked Since Feb 18, 2026