
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-6432 is a DNS proxy bypass vulnerability in Mozilla Firefox and Thunderbird titled "DNS Requests leaked outside of a configured SOCKS proxy." When the Multi-Account Containers extension is enabled and a SOCKS proxy is configured, DNS requests could bypass the proxy when the domain name is invalid or the SOCKS proxy is unresponsive — potentially exposing the user's browsing activity to network observers. The vulnerability affects Firefox versions before 140.0 and Thunderbird versions before 140.0. It was disclosed on June 24, 2025, and fixed in Firefox 140 (announced June 24, 2025) and Thunderbird 140 (announced July 2, 2025). Mozilla rated the impact as Low; Feedly's CVSS v3.1 estimate assigns a base score of 8.6 (High) (Mozilla Advisory, Mozilla Advisory).
The root cause is improper handling of speculative connections created by RemoteWebNavigation when the Multi-Account Containers (MAC) extension is active (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor). When Firefox initiates a speculative connection, it creates a dummy channel for proxy resolution; however, because no load context (and thus no valid tab ID) was provided, the MAC extension's proxy filter returned an empty proxy configuration for requests with tabId === -1. Without proxy info assigned, Firefox fell back to the system's default DNS resolver, causing DNS queries to leak outside the SOCKS proxy tunnel. The fix involved two patches: ensuring speculative connections from RemoteWebNavigation carry a valid tab ID, and disallowing speculative connections that lack callbacks when proxy filters are registered (Mozilla Bugzilla, Mozilla Advisory).
Exploitation of this vulnerability allows a network-level observer (e.g., an ISP, router operator, or local network attacker) to observe DNS queries that the user intended to route through a SOCKS proxy, thereby inferring which domains the user is visiting even when privacy-preserving proxy configurations are in place. The primary impact is a confidentiality breach — specifically, the leakage of browsing metadata — with low integrity and availability impact. Users relying on SOCKS proxies for anonymity or to circumvent network monitoring (e.g., in sensitive environments) are most at risk (Mozilla Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The vulnerability is passive in nature — an attacker positioned on the network path (e.g., a router or ISP) can observe leaked DNS queries without any active interaction with the victim. No threat actor attribution has been reported. The EPSS score is approximately 0.042% (0.000420), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Mozilla has released patches in Firefox 140 and Thunderbird 140, which fix the speculative connection proxy bypass. Users should update to Firefox 140.0 or later and Thunderbird 140.0 or later immediately. As a temporary workaround prior to patching, users can: (1) disable the Multi-Account Containers extension, (2) set DNS over HTTPS to "Max Protection" mode to prevent system DNS fallback, or (3) configure the SOCKS proxy at the OS level rather than relying solely on the extension. ESR versions (115 and 128) were assessed as wontfix by Mozilla given the low severity rating (Mozilla Advisory, Mozilla Bugzilla).
Mozilla classified the vulnerability as Low severity in its official advisory, consistent with the passive, network-observer-only exploitation model. Red Hat tracked the issue via Bugzilla (Bug 2374556) and also assessed it as low priority/severity. The CIS Security advisory for Thunderbird 140 referenced the vulnerability as part of a broader set of fixes. No significant independent researcher commentary or social media discussion has been identified beyond standard vulnerability aggregator coverage (Red Hat Bugzilla, Mozilla Advisory).
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
mozjs38
devel
firefox
jammy
thunderbird: 1:140.7.1+build1-0ubuntu0.22.04.1
noble
firefox
questing
firefox
resolute
firefox
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."