Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the target account. This vulnerability affects Firefox for iOS < 142 and Focus for iOS < 142.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-25225 Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the target account. This vulnerability affects Firefox for iOS < 142 and Focus for iOS < 142.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 31 Oct 2025 01:30:00 +0900

Type Values Removed Values Added
Title Passkey phishing within Bluetooth range

Fri, 22 Aug 2025 03:45:00 +0900

Type Values Removed Values Added
First Time appeared Mozilla firefox
Mozilla firefox Focus
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:mozilla:firefox_focus:*:*:*:*:*:iphone_os:*:*
Vendors & Products Mozilla firefox
Mozilla firefox Focus

Thu, 21 Aug 2025 21:45:00 +0900

Type Values Removed Values Added
First Time appeared Apple
Apple ios
Mozilla
Mozilla firefox For Ios
Mozilla focus For Ios
Vendors & Products Apple
Apple ios
Mozilla
Mozilla firefox For Ios
Mozilla focus For Ios

Thu, 21 Aug 2025 01:15:00 +0900

Type Values Removed Values Added
Weaknesses CWE-601
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 20 Aug 2025 06:00:00 +0900

Type Values Removed Values Added
Description Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the target account. This vulnerability affects Firefox for iOS < 142 and Focus for iOS < 142.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2025-10-30T16:11:09.283Z

Reserved: 2025-08-05T13:26:34.686Z

Link: CVE-2025-55031

cve-icon Vulnrichment

Updated: 2025-08-20T14:01:42.748Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-19T21:15:28.340

Modified: 2025-08-21T18:38:56.970

Link: CVE-2025-55031

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-21T21:31:42Z

Weaknesses