CVE-2025-1940

Description

A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue only affects Android versions of Firefox.*. This vulnerability was fixed in Firefox 136.

Risk Information

Base Score
7.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
EPSS Score
Exploitation Probability
0.276

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Mozilla Firefox (136.0)Windows
Multiple vulnerabilities are fixed in Mozilla Firefox (x64) (136.0)Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 135.99Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 135.99Windows
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (136.0)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (136.0.1)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (136.0.2)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (136.0.3)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (136.0.4)Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-345893Mozilla Firefox (136.0)
PATCH-345894Mozilla Firefox (x64) (136.0)
PATCH-351030Mozilla Firefox (x64) (142.0.1)
PATCH-351029Mozilla Firefox (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234