CVE-2025-6431

Source
https://cve.org/CVERecord?id=CVE-2025-6431
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-6431.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-6431
Downstream
Related
Published
2025-06-24T13:15:24.103Z
Modified
2026-04-10T05:33:44.445449Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have bypassed this prompt, potentially exposing the user to security vulnerabilities or privacy leaks in external applications. This bug only affects Firefox for Android. Other versions of Firefox are unaffected. This vulnerability affects Firefox < 140.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-6431.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "140.0"
            }
        ]
    }
]