CVE-2025-6433

🟠 Łataj w tym tygodniu

Naruszenie specyfikacji WebAuthn w Firefox i Thunderbird umożliwia nieautoryzowane wyzwania WebAuthn.

CVSS
9.8
EPSS
0.3%
Exploit
none
Vendor
mozilla
Opis źródłowy (NVD)

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability was fixed in Firefox 140 and Thunderbird 140.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2025-06-24 13:15:24 UTC
Ostatnia modyfikacja (NVD)2026-09-30 18:10:00 UTC
Referencje