CVE-2025-54145
published 2025-08-19CVE-2025-54145: The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL scheme…
PriorityP349critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.37%
29.0th percentile
The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL scheme. This vulnerability was fixed in Firefox for iOS 141.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < 141.0 | 141.0 |
| mozilla | firefox | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3879-gmgh-p53r: The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL
ghsa_unreviewed·2025-08-19
CVE-2025-54145 [CRITICAL] CWE-601 GHSA-3879-gmgh-p53r: The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL
The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL scheme This vulnerability affects Firefox for iOS < 141.
OSV
CVE-2025-54145: The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL
osv·2025-07-23·CVSS 9.1
CVE-2025-54145 [CRITICAL] CVE-2025-54145: The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL
The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL scheme. This vulnerability affects Firefox for iOS < 141.
Mozilla
Mozilla Foundation Security Advisory 2025-60: CVE-2025-54145
vendor_mozilla·CVSS 9.1
CVE-2025-54145 [CRITICAL] Mozilla Foundation Security Advisory 2025-60: CVE-2025-54145
Mozilla Foundation Security Advisory 2025-60
CVE: CVE-2025-54145
Product: Firefox for iOS
Impact: moderate
Fixed in: Firefox for iOS 141
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-19
Published