CVE-2025-0245
published 2025-01-07CVE-2025-0245: Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability was…
low3.3CVSS 3.1
AVLACLPRNUIRSUCLINAN
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability was fixed in Firefox 134.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 134.0 | 134.0 |
| mozilla | firefox | < 136.0 | 136.0 |
| mozilla | firefox | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv3.3LOW
OSV
CVE-2025-1941: Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-
osv·2025-03-04·CVSS 3.3
CVE-2025-1941 [LOW] CVE-2025-1941: Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability affects Firefox < 136.
GHSA
GHSA-m793-xp46-r76w: Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-
ghsa_unreviewed·2025-03-04·CVSS 3.3
CVE-2025-1941 [LOW] CWE-284 GHSA-m793-xp46-r76w: Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability affects Firefox < 136.
OSV
CVE-2025-0245: Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed
osv·2025-01-07·CVSS 3.3
CVE-2025-0245 [LOW] CVE-2025-0245: Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability affects Firefox < 134.
GHSA
GHSA-2g52-qw8q-wfr9: Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed
ghsa_unreviewed·2025-01-07
CVE-2025-0245 [LOW] GHSA-2g52-qw8q-wfr9: Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability affects Firefox < 134.
Red Hat
firefox: Lock screen setting bypass in Firefox Focus for Android
vendor_redhat·2025-03-04·CVSS 3.3
CVE-2025-1941 [LOW] CWE-306 firefox: Lock screen setting bypass in Firefox Focus for Android
firefox: Lock screen setting bypass in Firefox Focus for Android
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability affects Firefox < 136.
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue: Under certain circumstances, a user opt-in setting that Focus should require authentication before use could be bypassed (distinct from CVE-2025-0245).
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
This CVE is specific to Firefox Focus for Android. No Red Hat products are affected.
Package: firefox (Red Hat Enterprise Linux 10) - Fix deferre
Red Hat
firefox: Lock screen setting bypass in Firefox Focus for Android
vendor_redhat·2025-01-07·CVSS 3.3
CVE-2025-0245 [LOW] CWE-288 firefox: Lock screen setting bypass in Firefox Focus for Android
firefox: Lock screen setting bypass in Firefox Focus for Android
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability affects Firefox < 134.
The Mozilla Foundation's Security Advisory: Under certain circumstances, a user opt-in setting that Focus should require authentication before use could be bypassed.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. This vulnerability is specific to Firefox Focus in Android. Red Hat is not affected.
Package: firefox (Red Hat Enterprise Linux 10) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not af
Debian
CVE-2025-0245: firefox - Under certain circumstances, a user opt-in setting that Focus should require aut...
vendor_debian·2025·CVSS 3.3
CVE-2025-0245 [LOW] CVE-2025-0245: firefox - Under certain circumstances, a user opt-in setting that Focus should require aut...
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability affects Firefox < 134.
Scope: local
sid: resolved
Debian
CVE-2025-1941: firefox - Under certain circumstances, a user opt-in setting that Focus should require aut...
vendor_debian·2025·CVSS 3.3
CVE-2025-1941 [LOW] CVE-2025-1941: firefox - Under certain circumstances, a user opt-in setting that Focus should require aut...
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability affects Firefox < 136.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2025-14: CVE-2025-0245
vendor_mozilla·CVSS 3.3
CVE-2025-0245 [LOW] Mozilla Foundation Security Advisory 2025-14: CVE-2025-0245
Mozilla Foundation Security Advisory 2025-14
CVE: CVE-2025-0245
Product: Firefox
Impact: high
Fixed in: Firefox 136
Mozilla
Mozilla Foundation Security Advisory 2025-01: CVE-2025-0245
vendor_mozilla·CVSS 3.3
CVE-2025-0245 [LOW] Mozilla Foundation Security Advisory 2025-01: CVE-2025-0245
Mozilla Foundation Security Advisory 2025-01
CVE: CVE-2025-0245
Product: Firefox
Impact: high
Fixed in: Firefox 134
No detection rules found.
No public exploits indexed.
2025-01-07
Published