CVE-2025-6427: firefox: connect-src Content Security Policy restriction could be bypassed

Severity: Critical

CVSS Score: 9.1

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140 and Thunderbird < 140.