#VU105321 Improper Restriction of Rendered UI Layers or Frames in Firefox for Android - CVE-2025-1939
Published: March 5, 2025
Firefox for Android
Mozilla
Description
The vulnerability allows a remote attacker to perform tapjacking attacks.
The vulnerability exists due to the way Android tabs load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking.