Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-1939

Опубликовано: 04 мар. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 3.9

Описание

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.

РелизСтатусПримечание
devel

not-affected

code not present
esm-infra/focal

DNE

focal

not-affected

Android-specific
jammy

not-affected

code not present
noble

not-affected

code not present
oracular

not-affected

code not present
plucky

not-affected

code not present
upstream

not-affected

debian: Android-specific

Показывать по

РелизСтатусПримечание
devel

not-affected

code not present
esm-infra/focal

DNE

focal

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
oracular

not-affected

code not present
plucky

not-affected

code not present
upstream

needs-triage

Показывать по

EPSS

Процентиль: 1%
0.0001
Низкий

3.9 Low

CVSS3

Связанные уязвимости

CVSS3: 7.1
redhat
7 месяцев назад

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.

CVSS3: 3.9
nvd
7 месяцев назад

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.

CVSS3: 3.9
debian
7 месяцев назад

Android apps can load web pages using the Custom Tabs feature. This fe ...

CVSS3: 3.9
github
7 месяцев назад

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.

EPSS

Процентиль: 1%
0.0001
Низкий

3.9 Low

CVSS3