Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-1939

Опубликовано: 04 мар. 2025
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.

A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue: Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could be used to trick a user into granting sensitive permissions by hiding what the user is actually clicking.

Отчет

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. This CVE is specific to Firefox for Android.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10firefoxFix deferred
Red Hat Enterprise Linux 10firefox-flatpak-containerFix deferred
Red Hat Enterprise Linux 6firefoxFix deferred
Red Hat Enterprise Linux 7firefoxFix deferred
Red Hat Enterprise Linux 8firefoxFix deferred
Red Hat Enterprise Linux 9firefoxFix deferred
Red Hat Enterprise Linux 9firefox-flatpak-containerFix deferred

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1021
https://bugzilla.redhat.com/show_bug.cgi?id=2349798firefox: Tapjacking in Android Custom Tabs using transition animations

EPSS

Процентиль: 2%
0.00013
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 3.9
ubuntu
7 месяцев назад

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.

CVSS3: 3.9
nvd
7 месяцев назад

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.

CVSS3: 3.9
debian
7 месяцев назад

Android apps can load web pages using the Custom Tabs feature. This fe ...

CVSS3: 3.9
github
7 месяцев назад

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.

EPSS

Процентиль: 2%
0.00013
Низкий

7.1 High

CVSS3