CVE-2025-6432
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-6432 is a DNS proxy bypass vulnerability in Mozilla Firefox and Thunderbird titled "DNS Requests leaked outside of a configured SOCKS proxy." When the Multi-Account Containers extension is enabled and a SOCKS proxy is configured, DNS requests could bypass the proxy when the domain name is invalid or the SOCKS proxy is unresponsive — potentially exposing the user's browsing activity to network observers. The vulnerability affects Firefox versions before 140.0 and Thunderbird versions before 140.0. It was disclosed on June 24, 2025, and fixed in Firefox 140 (announced June 24, 2025) and Thunderbird 140 (announced July 2, 2025). Mozilla rated the impact as Low; Feedly's CVSS v3.1 estimate assigns a base score of 8.6 (High) (Mozilla Advisory, Mozilla Advisory).

Technical details

The root cause is improper handling of speculative connections created by RemoteWebNavigation when the Multi-Account Containers (MAC) extension is active (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor). When Firefox initiates a speculative connection, it creates a dummy channel for proxy resolution; however, because no load context (and thus no valid tab ID) was provided, the MAC extension's proxy filter returned an empty proxy configuration for requests with tabId === -1. Without proxy info assigned, Firefox fell back to the system's default DNS resolver, causing DNS queries to leak outside the SOCKS proxy tunnel. The fix involved two patches: ensuring speculative connections from RemoteWebNavigation carry a valid tab ID, and disallowing speculative connections that lack callbacks when proxy filters are registered (Mozilla Bugzilla, Mozilla Advisory).

Impact

Exploitation of this vulnerability allows a network-level observer (e.g., an ISP, router operator, or local network attacker) to observe DNS queries that the user intended to route through a SOCKS proxy, thereby inferring which domains the user is visiting even when privacy-preserving proxy configurations are in place. The primary impact is a confidentiality breach — specifically, the leakage of browsing metadata — with low integrity and availability impact. Users relying on SOCKS proxies for anonymity or to circumvent network monitoring (e.g., in sensitive environments) are most at risk (Mozilla Advisory, Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The vulnerability is passive in nature — an attacker positioned on the network path (e.g., a router or ISP) can observe leaked DNS queries without any active interaction with the victim. No threat actor attribution has been reported. The EPSS score is approximately 0.042% (0.000420), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Precondition: The target user must have Firefox (< 140.0) with the Multi-Account Containers extension installed and a SOCKS proxy configured for a container.
  2. Position on network: The attacker positions themselves to observe DNS traffic from the victim's network (e.g., on the same LAN, at a router, or at an ISP level) using a packet capture tool such as Wireshark or tcpdump.
  3. Trigger the leak: The victim navigates to a URL with an invalid or mistyped domain name within a proxied container, or the configured SOCKS proxy is temporarily unresponsive. Firefox's speculative connection mechanism initiates a DNS lookup without proxy context.
  4. Observe leaked DNS queries: Because the speculative connection lacks a valid tab ID, the MAC extension does not assign proxy info, and Firefox resolves the domain via the system's default DNS resolver. The attacker captures these DNS queries in plaintext on the network, revealing the domains the user intended to visit privately (Mozilla Bugzilla).

Indicators of compromise

  • Network: DNS queries originating from the Firefox host's IP address (rather than the SOCKS proxy server's IP) for domains that should be resolved through the proxy; observable via packet capture (Wireshark/tcpdump) on the local network or upstream router.
  • Logs: Router or DNS server logs showing DNS resolution requests from the affected Firefox host for domains that the user was browsing in a proxied Multi-Account Container.
  • Process/Browser: Firefox version below 140.0 running with the Multi-Account Containers extension and a SOCKS proxy configured — this combination is the prerequisite for the leak to occur.

Mitigation and workarounds

Mozilla has released patches in Firefox 140 and Thunderbird 140, which fix the speculative connection proxy bypass. Users should update to Firefox 140.0 or later and Thunderbird 140.0 or later immediately. As a temporary workaround prior to patching, users can: (1) disable the Multi-Account Containers extension, (2) set DNS over HTTPS to "Max Protection" mode to prevent system DNS fallback, or (3) configure the SOCKS proxy at the OS level rather than relying solely on the extension. ESR versions (115 and 128) were assessed as wontfix by Mozilla given the low severity rating (Mozilla Advisory, Mozilla Bugzilla).

Community reactions

Mozilla classified the vulnerability as Low severity in its official advisory, consistent with the passive, network-observer-only exploitation model. Red Hat tracked the issue via Bugzilla (Bug 2374556) and also assessed it as low priority/severity. The CIS Security advisory for Thunderbird 140 referenced the vulnerability as part of a broader set of fixes. No significant independent researcher commentary or social media discussion has been identified beyond standard vulnerability aggregator coverage (Red Hat Bugzilla, Mozilla Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

sid

firefox: 140.0-1

Fixed

Ubuntu

Fixed

bionic (esm-apps)

mozjs38

Unknown

devel

firefox

Not Affected

jammy

thunderbird: 1:140.7.1+build1-0ubuntu0.22.04.1

Fixed

noble

firefox

Not Affected

questing

firefox

Not Affected

resolute

firefox

Not Affected

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

RHEL 10

Not Affected

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86993MEDIUM5.9
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86996MEDIUM5.3
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86995MEDIUM5.3
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86994MEDIUM5.3
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86085MEDIUM5.1
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management