CVE-2025-6431
published 2025-06-24CVE-2025-6431: When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have bypassed…
PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.21%
11.3th percentile
When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have bypassed this prompt, potentially exposing the user to security vulnerabilities or privacy leaks in external applications.
*This bug only affects Firefox for Android. Other versions of Firefox are unaffected.*. This vulnerability was fixed in Firefox 140.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 140.0 | 140.0 |
| mozilla | firefox | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jh8f-wj26-59hv: When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so
ghsa_unreviewed·2025-06-26
CVE-2025-6431 [MEDIUM] CWE-285 GHSA-jh8f-wj26-59hv: When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so
When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have bypassed this prompt, potentially exposing the user to security vulnerabilities or privacy leaks in external applications.
*This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140.
OSV
CVE-2025-6431: When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so
osv·2025-06-24·CVSS 6.5
CVE-2025-6431 [MEDIUM] CVE-2025-6431: When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so
When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have bypassed this prompt, potentially exposing the user to security vulnerabilities or privacy leaks in external applications. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140.
Red Hat
firefox: The prompt in Firefox for Android that asks before opening a link in an external application could be bypassed
vendor_redhat·2025-06-24·CVSS 6.5
CVE-2025-6431 [MEDIUM] firefox: The prompt in Firefox for Android that asks before opening a link in an external application could be bypassed
firefox: The prompt in Firefox for Android that asks before opening a link in an external application could be bypassed
When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have bypassed this prompt, potentially exposing the user to security vulnerabilities or privacy leaks in external applications.
*This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.*
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 10) - Not affected
Package
Red Hat
kernel: platform/x86/amd/pmc: Only disable IRQ1 wakeup where i8042 actually enabled it
vendor_redhat·2025-01-19·CVSS 5.5
CVE-2025-21645 [MEDIUM] CWE-20 kernel: platform/x86/amd/pmc: Only disable IRQ1 wakeup where i8042 actually enabled it
kernel: platform/x86/amd/pmc: Only disable IRQ1 wakeup where i8042 actually enabled it
In the Linux kernel, the following vulnerability has been resolved:
platform/x86/amd/pmc: Only disable IRQ1 wakeup where i8042 actually enabled it
Wakeup for IRQ1 should be disabled only in cases where i8042 had
actually enabled it, otherwise "wake_depth" for this IRQ will try to
drop below zero and there will be an unpleasant WARN() logged:
kernel: atkbd serio0: Disabling IRQ1 wakeup source to avoid platform firmware bug
kernel: ------------[ cut here ]------------
kernel: Unbalanced IRQ 1 wake disable
kernel: WARNING: CPU: 10 PID: 6431 at kernel/irq/manage.c:920 irq_set_irq_wake+0x147/0x1a0
The PMC driver uses DEFINE_SIMPLE_DEV_PM_OPS() to define its dev_pm_ops
which sets amd_pmc_suspend_handler() to
Debian
CVE-2025-6431: firefox - When a link can be opened in an external application, Firefox for Android will, ...
vendor_debian·2025·CVSS 6.5
CVE-2025-6431 [MEDIUM] CVE-2025-6431: firefox - When a link can be opened in an external application, Firefox for Android will, ...
When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have bypassed this prompt, potentially exposing the user to security vulnerabilities or privacy leaks in external applications. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2025-51: CVE-2025-6431
vendor_mozilla·CVSS 6.5
CVE-2025-6431 [MEDIUM] Mozilla Foundation Security Advisory 2025-51: CVE-2025-6431
Mozilla Foundation Security Advisory 2025-51
CVE: CVE-2025-6431
Product: Firefox
Impact: high
Fixed in: Firefox 140
No detection rules found.
No public exploits indexed.
2025-06-24
Published