Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6rx2-wjr5-47v3

Опубликовано: 19 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the target account. This vulnerability affects Firefox for iOS < 142 and Focus for iOS < 142.

Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the target account. This vulnerability affects Firefox for iOS < 142 and Focus for iOS < 142.

EPSS

Процентиль: 17%
0.00055
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 9.8
nvd
29 дней назад

Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the target account. This vulnerability affects Firefox for iOS < 142 and Focus for iOS < 142.

CVSS3: 2.6
fstec
30 дней назад

Уязвимость браузера Mozilla Firefox, связанная с раскрытием информации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 17%
0.00055
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-601