PT-2025-26728 · Mozilla+2 · Firefox For Android+2

Umar Farooq

·

Published

2025-06-24

·

Updated

2025-11-19

·

CVE-2025-6431

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions: Firefox for Android versions prior to 140
Description: The issue allows an attacker to bypass the default prompt that appears when a link can be opened in an external application, potentially exposing the user to security risks or privacy leaks in external applications.
Recommendations: For Firefox for Android versions prior to 140, update to version 140 or later to resolve the issue.

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-11100
ALT-PU-2025-11497
ALT-PU-2025-14599
ALT-PU-2025-8725
BDU:2025-08994
CVE-2025-6431
OPENSUSE-SU-2025:15325-1
OPENSUSE-SU-2025:15371-1
SUSE-SU-2025:02339-1
SUSE-SU-2025:02529-1
SUSE-SU-2025_02339-1
SUSE-SU-2025_02529-1

Affected Products

Alt Linux
Firefox For Android
Suse