CVE-2025-6426

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
24/06/2025
Last modified:
13/04/2026

Description

The executable file warning did not warn users before opening files with the `terminal` extension. <br /> *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.*. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* 128.12.0 (excluding)
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* 140.0 (excluding)
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*