Vulnerability CVE-2025-1939: Information
Description
Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
firefox | sisyphus | 136.0-alt1 | 136.0.2-alt1 | ALT-PU-2025-4104-2 | 376916 | Fixed |
firefox | sisyphus_loongarch64 | 136.0.1-alt0.port | 136.0.1-alt0.port | ALT-PU-2025-4467-1 | - | Fixed |
firefox | p11 | 136.0.2-alt1 | 135.0.1-alt1 | ALT-PU-2025-4567-1 | 378599 | Testing |