Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-1940

Опубликовано: 04 мар. 2025
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. This issue only affects Android versions of Firefox. This vulnerability affects Firefox < 136.

A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue: A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly.

Отчет

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. This issue only affects Android versions of Firefox.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10firefoxNot affected
Red Hat Enterprise Linux 10firefox-flatpak-containerNot affected
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 7firefoxNot affected
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 9firefoxNot affected
Red Hat Enterprise Linux 9firefox-flatpak-containerNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-451
https://bugzilla.redhat.com/show_bug.cgi?id=2349788firefox: Android Intent confirmation prompt tapjacking using Select options

EPSS

Процентиль: 27%
0.00097
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
10 месяцев назад

A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 136.

CVSS3: 7.1
nvd
10 месяцев назад

A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 136.

CVSS3: 7.1
debian
10 месяцев назад

A select option could partially obscure the confirmation prompt shown ...

CVSS3: 7.1
github
10 месяцев назад

A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 136.

EPSS

Процентиль: 27%
0.00097
Низкий

5.4 Medium

CVSS3

Уязвимость CVE-2025-1940