External risk intelligence

Firefox and Thunderbird WebAuthn Challenge Bypass with Invalid TLS Certificate

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-6433

This vulnerability requires a user to manually interact with a web browser by visiting a malicious webpage, accepting an invalid TLS certificate, and then actively completing a WebAuthn prompt. It is a client-side issue dependent on specific user action rather than an exposed network service, gateway, or internet-facing infrastructure.

Mozilla Firefox

before 140.0

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security issue has been identified in web browsing technology that could allow a malicious website to present a fraudulent security prompt to users, even after they have bypassed warnings about an invalid security certificate. This could potentially lead to unauthorized actions if a user proceeds to complete the prompted security step. The main concern is confirming relevance and exposure.

  • Bypassing security warnings can lead to user deception.
  • Leadership should remember issues impacting user trust.
  • Confirm relevance and potential exposure to user actions.

Attack Path

How an attacker could exploit the issue

An attacker could trick a user into visiting a specially crafted webpage that presents an invalid TLS certificate. If the user bypasses the security warning for the certificate, the attacker-controlled page can then prompt the user to complete a WebAuthn challenge, potentially leading to a compromise.

  • User visits a malicious webpage.
  • User accepts invalid TLS certificate.
  • WebAuthn prompt can be triggered.

Live Threat

Current exploitation, exposure, and threat context

When a user visits a webpage with an invalid TLS certificate and proceeds despite a warning, a WebAuthn prompt could be presented. This bypasses the requirement for secure transport, potentially affecting the integrity of authentication processes.

  • User authentication data could be exposed.
  • User is tricked into a malicious prompt.
  • Compromised user account access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability, which allows a webpage to bypass security by exploiting user interaction with invalid TLS certificates and WebAuthn challenges, likely falls under the purview of application owners and potentially platform teams if the affected browsers are managed centrally. The first practical step involves identifying all instances of the affected browser across the organization, assessing their exposure based on user access patterns, and confirming which business-critical functions or data might be impacted before planning remediation.

  • Application owners should confirm browser usage.
  • Verify user interaction with invalid certificates.
  • Plan browser updates based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Mozilla Firefox and how is it used?

Mozilla Firefox is a widely used open-source web browser that renders web pages and executes various web technologies. It is built to support modern security standards, including WebAuthn, which allows users to authenticate to websites using hardware keys or biometric sensors as a secure alternative to passwords.

What does CVE-2025-6433 mean by improper certificate validation?

This vulnerability, classified as CWE-295 (Improper Certificate Validation), refers to a flaw where the browser fails to maintain secure transport requirements. Specifically, it allows a website to invoke a WebAuthn challenge even when the underlying connection's TLS certificate is invalid, violating the standard that requires a connection to be error-free before such requests occur.

How can an attacker trigger this security flaw?

An attacker triggers this by hosting a malicious webpage with an invalid TLS certificate. The flaw does not activate automatically; it requires the user to ignore the browser's security warning, accept the invalid certificate, and subsequently interact with and complete the deceptive WebAuthn prompt presented by the site.

Is this CVE a risk for my internet-facing servers?

According to Halo Surface Signal, this is unlikely to impact your infrastructure servers. Because the issue is a client-side browser vulnerability that relies on active user interaction—specifically ignoring certificate warnings and performing manual authentication steps—it is not an exposed service or gateway flaw.

What steps should I take to address CVE-2025-6433?

The primary response is to update your browser software. Firefox and Thunderbird users should ensure their applications are upgraded to version 140 or higher, which contains the fix for this issue. Administratively, identify where these browsers are deployed and prioritize updates for systems where users frequently access sensitive business applications.

References