Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the target account. This vulnerability affects Firefox for iOS < 142 and Focus for iOS < 142.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Aug 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apple
Apple ios Mozilla Mozilla firefox For Ios Mozilla focus For Ios |
|
Vendors & Products |
Apple
Apple ios Mozilla Mozilla firefox For Ios Mozilla focus For Ios |
Wed, 20 Aug 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-601 | |
Metrics |
cvssV3_1
|
Tue, 19 Aug 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the target account. This vulnerability affects Firefox for iOS < 142 and Focus for iOS < 142. | |
References |
|

Status: PUBLISHED
Assigner: mozilla
Published: 2025-08-19T20:52:49.748Z
Updated: 2025-08-20T15:17:12.739Z
Reserved: 2025-08-05T13:26:34.686Z
Link: CVE-2025-55031

Updated: 2025-08-20T14:01:42.748Z

Status : Undergoing Analysis
Published: 2025-08-19T21:15:28.340
Modified: 2025-08-20T16:15:42.073
Link: CVE-2025-55031

No data.