When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have bypassed this prompt, potentially exposing the user to security vulnerabilities or privacy leaks in external applications. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.*. This vulnerability was fixed in Firefox 140.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade MozillaFirefox-translations-otherUpgrade pipewire-spa-plugins-0_2Upgrade xdg-desktop-portal-develUpgrade mozillafirefox-branding-sleUpgrade pipewire-modulesUpgrade xdg-desktop-portal-langUpgrade pipewireUpgrade MozillaFirefoxUpgrade pipewire-spa-toolsUpgrade pipewire-langUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-develUpgrade pipewire-modules-0_3Upgrade mozillafirefox-branding-upstreamUpgrade xdg-desktop-portalUpgrade gstreamer-plugin-pipewireUpgrade libpipewire-0_3-0Upgrade pipewire-tools | Jul 22, 2025 | Jun 24, 2025 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jun 24, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub