CVE-2025-6432High· 8.6▾ TwilightWhen Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not responding. This vulnerability was fixed in Firefox 140 and Thunderbird 140.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not responding. This vulnerability was fixed in Firefox 140 and Thunderbird 140.
firefox < 140.0Upgrade past the affected range:
firefox 140.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-96869Medium· 4.3Information disclosure in the Networking component
CVE-2026-100766Medium· 4.3Information disclosure in the Networking: JAR component
CVE-2026-92070Medium· 4.3Information disclosure in the Networking component
CVE-2026-8706Medium· 6.5Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies
CVE-2026-8967High· 7.5Information disclosure in the Graphics: WebGPU component
CVE-2026-8966High· 7.5Information disclosure in the IP Protection component