Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-1939

Опубликовано: 04 мар. 2025
Источник: nvd
CVSS3: 3.9
EPSS Низкий

Описание

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
Версия до 136.0 (исключая)

EPSS

Процентиль: 2%
0.00014
Низкий

3.9 Low

CVSS3

Дефекты

CWE-359

Связанные уязвимости

CVSS3: 3.9
ubuntu
7 месяцев назад

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.

CVSS3: 7.1
redhat
7 месяцев назад

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.

CVSS3: 3.9
debian
7 месяцев назад

Android apps can load web pages using the Custom Tabs feature. This fe ...

CVSS3: 3.9
github
7 месяцев назад

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.

EPSS

Процентиль: 2%
0.00014
Низкий

3.9 Low

CVSS3

Дефекты

CWE-359