Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-1940

Опубликовано: 04 мар. 2025
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. This issue only affects Android versions of Firefox.. This vulnerability was fixed in Firefox 136.

A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue: A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly.

Отчет

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. This issue only affects Android versions of Firefox.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10firefoxNot affected
Red Hat Enterprise Linux 10firefox-flatpak-containerNot affected
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 7firefoxNot affected
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 9firefoxNot affected
Red Hat Enterprise Linux 9firefox-flatpak-containerNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-451
https://bugzilla.redhat.com/show_bug.cgi?id=2349788firefox: Android Intent confirmation prompt tapjacking using Select options

EPSS

Процентиль: 15%
0.0024
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 1 года назад

A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue only affects Android versions of Firefox.*. This vulnerability was fixed in Firefox 136.

CVSS3: 7.1
nvd
больше 1 года назад

A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue only affects Android versions of Firefox.*. This vulnerability was fixed in Firefox 136.

CVSS3: 7.1
debian
больше 1 года назад

A select option could partially obscure the confirmation prompt shown ...

CVSS3: 7.1
github
больше 1 года назад

A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 136.

EPSS

Процентиль: 15%
0.0024
Низкий

5.4 Medium

CVSS3