CVE-2025-1939: Mozilla Firefox

Low severity, CVSS 3.9. EPSS: 0.2% chance of exploitation in the next 30 days.

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability was fixed in Firefox 136.

Affected products

  • Mozilla Firefox: before 136.0 (fixed in 136.0)

Published 2025-03-04. Last modified 2026-10-05.