Vulnerability CVE-2025-1940: Information
Description
A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue only affects Android versions of Firefox.*. This vulnerability was fixed in Firefox 136.
Severity: HIGH (7.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
|---|---|---|---|---|---|---|
| firefox | sisyphus | 136.0-alt1 | 150.0.2-alt1 | ALT-PU-2025-4104-3 | 376916 | Fixed |
| firefox | sisyphus_riscv64 | 137.0.2-alt0.port | 149.0.2-alt0.port | ALT-PU-2025-5736-1 | - | Fixed |
| firefox | sisyphus_loongarch64 | 136.0.1-alt0.port | 149.0.2-alt0.port | ALT-PU-2025-4467-1 | - | Fixed |
| firefox | p11 | 136.0.2-alt1 | 149.0-alt1 | ALT-PU-2025-4567-3 | 378599 | Fixed |
| firefox | p10 | 138.0.1-alt0.p10.1 | 141.0.2-alt0.p10.1 | ALT-PU-2025-7697-3 | 385484 | Fixed |
| firefox | c10f2 | 141.0.3-alt0.c10f2.1 | 141.0.3-alt0.c10f2.1 | ALT-PU-2025-11607-6 | 394393 | Fixed |
| firefox-esr | sisyphus | 140.2.0-alt2 | 140.9.1-alt1 | ALT-PU-2025-11092-4 | 393694 | Fixed |
| firefox-esr | sisyphus_loongarch64 | 140.9.1-alt0.port | 140.9.1-alt0.port | ALT-PU-2026-6293-1 | - | Fixed |
| firefox-esr | p11 | 140.2.0-alt2 | 140.9.1-alt1 | ALT-PU-2025-11100-5 | 393714 | Fixed |
| firefox-esr | p10 | 140.4.0-alt0.p10.1 | 140.9.1-alt0.p10.1 | ALT-PU-2025-14599-5 | 396669 | Fixed |
| firefox-esr | c10f2 | 140.2.0-alt0.c10.1 | 140.9.1-alt1 | ALT-PU-2025-11165-5 | 393749 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=1908488 |
|
| https://www.mozilla.org/security/advisories/mfsa2025-14/ |
|