CVE-2025-10530Authentication Bypass by Spoofing in Mozilla Firefox

Severity
6.5MEDIUMNVD
EPSS
0.0%
top 87.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 16

Description

Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 143 and Thunderbird 143.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5

Affected Packages2 packages

NVDmozilla/firefox< 143.0
NVDmozilla/thunderbird< 143.0

🔴Vulnerability Details

3
OSV
CVE-2025-10530: Spoofing issue in the WebAuthn component in Firefox for Android2025-09-16
CVEList
Spoofing issue in the WebAuthn component in Firefox for Android2025-09-16
GHSA
GHSA-hmr9-3q48-52hr: This vulnerability affects Firefox < 143 and Thunderbird < 1432025-09-16

📋Vendor Advisories

4
Red Hat
firefox: Spoofing issue in the WebAuthn component in Firefox for Android2025-09-16
Debian
CVE-2025-10530: firefox - Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerabil...2025
Mozilla
Mozilla Foundation Security Advisory 2025-77: CVE-2025-10530
Mozilla
Mozilla Foundation Security Advisory 2025-73: CVE-2025-10530
CVE-2025-10530 — Authentication Bypass by Spoofing | cvebase