CVE-2025-1939
published 2025-03-04CVE-2025-1939: Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into…
low3.9CVSS 3.1
AVLACLPRLUIRSUCLILAN
Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability was fixed in Firefox 136.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| linux | linux_kernel | >= 6.13.0 < 6.18.3 | 6.18.3 |
| linux | linux_kernel | >= 6.5.0 < 6.6.120 | 6.6.120 |
| linux | linux_kernel | >= 6.7.0 < 6.12.64 | 6.12.64 |
| mozilla | firefox | < 136.0 | 136.0 |
| mozilla | firefox | — | — |
CVSS provenance
nvdv3.13.9LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
osv5.5MEDIUM
OSV
f2fs: ensure node page reads complete before f2fs_put_super() finishes
osv·2026-01-14·CVSS 5.5
CVE-2025-71107 f2fs: ensure node page reads complete before f2fs_put_super() finishes
f2fs: ensure node page reads complete before f2fs_put_super() finishes
In the Linux kernel, the following vulnerability has been resolved:
f2fs: ensure node page reads complete before f2fs_put_super() finishes
Xfstests generic/335, generic/336 sometimes crash with the following message:
F2FS-fs (dm-0): detect filesystem reference count leak during umount, type: 9, count: 1
------------[ cut here ]------------
kernel BUG at fs/f2fs/super.c:1939!
Oops: invalid opcode: 0000 [#1] SMP NOPTI
CPU: 1 UID: 0 PID: 609351 Comm: umount Tainted: G W 6.17.0-rc5-xfstests-g9dd1835ecda5 #1 PREEMPT(none)
Tainted: [W]=WARN
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:f2fs_put_super+0x3b3/0x3c0
Call Trace:
generic_shutdown_super+0x7e/0x190
kill_bloc
GHSA
GHSA-x9h6-qwxm-528g: Android apps can load web pages using the Custom Tabs feature
ghsa_unreviewed·2025-03-04
CVE-2025-1939 [LOW] CWE-359 GHSA-x9h6-qwxm-528g: Android apps can load web pages using the Custom Tabs feature
Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.
OSV
CVE-2025-1939: Android apps can load web pages using the Custom Tabs feature
osv·2025-03-04·CVSS 3.9
CVE-2025-1939 [LOW] CVE-2025-1939: Android apps can load web pages using the Custom Tabs feature
Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.
Red Hat
kernel: f2fs: ensure node page reads complete before f2fs_put_super() finishes
vendor_redhat·2026-01-14·CVSS 5.5
CVE-2025-71107 [MEDIUM] kernel: f2fs: ensure node page reads complete before f2fs_put_super() finishes
kernel: f2fs: ensure node page reads complete before f2fs_put_super() finishes
In the Linux kernel, the following vulnerability has been resolved:
f2fs: ensure node page reads complete before f2fs_put_super() finishes
Xfstests generic/335, generic/336 sometimes crash with the following message:
F2FS-fs (dm-0): detect filesystem reference count leak during umount, type: 9, count: 1
------------[ cut here ]------------
kernel BUG at fs/f2fs/super.c:1939!
Oops: invalid opcode: 0000 [#1] SMP NOPTI
CPU: 1 UID: 0 PID: 609351 Comm: umount Tainted: G W 6.17.0-rc5-xfstests-g9dd1835ecda5 #1 PREEMPT(none)
Tainted: [W]=WARN
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:f2fs_put_super+0x3b3/0x3c0
Call Trace:
generic_shutdown_super+0x7e/0x190
kill
Red Hat
firefox: Tapjacking in Android Custom Tabs using transition animations
vendor_redhat·2025-03-04·CVSS 3.9
CVE-2025-1939 [LOW] CWE-1021 firefox: Tapjacking in Android Custom Tabs using transition animations
firefox: Tapjacking in Android Custom Tabs using transition animations
Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue: Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could be used to trick a user into granting sensitive permissions by hiding what the user is actually clicking.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Adviso
Debian
CVE-2025-1939: firefox - Android apps can load web pages using the Custom Tabs feature. This feature supp...
vendor_debian·2025·CVSS 3.9
CVE-2025-1939 [LOW] CVE-2025-1939: firefox - Android apps can load web pages using the Custom Tabs feature. This feature supp...
Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2025-14: CVE-2025-1939
vendor_mozilla·CVSS 3.9
CVE-2025-1939 [LOW] Mozilla Foundation Security Advisory 2025-14: CVE-2025-1939
Mozilla Foundation Security Advisory 2025-14
CVE: CVE-2025-1939
Product: Firefox
Impact: high
Fixed in: Firefox 136
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-04
Published