When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have bypassed this prompt, potentially exposing the user to security vulnerabilities or privacy leaks in external applications. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.*. This vulnerability was fixed in Firefox 140.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade gstreamer-plugin-pipewireUpgrade mozillafirefox-branding-upstreamUpgrade pipewire-modules-0_3Upgrade MozillaFirefox-translations-commonUpgrade pipewire-toolsUpgrade libpipewire-0_3-0Upgrade xdg-desktop-portalUpgrade MozillaFirefox-develUpgrade pipewire-spa-plugins-0_2Upgrade pipewire-spa-toolsUpgrade MozillaFirefoxUpgrade xdg-desktop-portal-develUpgrade pipewire-langUpgrade MozillaFirefox-translations-otherUpgrade pipewire-modulesUpgrade xdg-desktop-portal-langUpgrade pipewireUpgrade mozillafirefox-branding-sle | Jul 22, 2025 | Jun 24, 2025 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jun 24, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub