When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have bypassed this prompt, potentially exposing the user to security vulnerabilities or privacy leaks in external applications. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140.
History

Thu, 03 Jul 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Mozilla
Mozilla firefox
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google
Google android
Mozilla
Mozilla firefox

Thu, 26 Jun 2025 00:30:00 +0000

Type Values Removed Values Added
Title firefox: The prompt in Firefox for Android that asks before opening a link in an external application could be bypassed
References
Metrics threat_severity

None

threat_severity

Low


Wed, 25 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 24 Jun 2025 12:45:00 +0000

Type Values Removed Values Added
Description When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have bypassed this prompt, potentially exposing the user to security vulnerabilities or privacy leaks in external applications. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2025-06-24T12:28:03.475Z

Updated: 2025-06-25T12:41:56.162Z

Reserved: 2025-06-20T14:51:36.769Z

Link: CVE-2025-6431

cve-icon Vulnrichment

Updated: 2025-06-25T12:33:59.279Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-24T13:15:24.103

Modified: 2025-07-03T16:04:21.163

Link: CVE-2025-6431

cve-icon Redhat

Severity : Low

Publid Date: 2025-06-24T12:28:03Z

Links: CVE-2025-6431 - Bugzilla