CVE-2025-1940: Mozilla Firefox

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue only affects Android versions of Firefox.*. This vulnerability was fixed in Firefox 136.

Affected products

  • Mozilla Firefox: before 136.0 (fixed in 136.0)

Published 2025-03-04. Last modified 2026-09-30.