CVE-2025-1935: Clickjacking the registerProtocolHandler info-bar
Published Mar 4, 2025
·Updated
A web page could trick a user into setting that site as the default handler for a custom URL protocol.
Affected Software
13 affected componentsFixes available
Mozilla Firefox<136
Mozilla Firefox ESR<128.8
Mozilla Firefox<136
136
Mozilla Firefox ESR<128.8
128.8
Mozilla Thunderbird<136
136
debian/firefox
136.0.1-1
debian/firefox-esr<=115.14.0esr-1~deb11u1, <=128.5.0esr-1~deb12u1
128.8.0esr-1~deb11u1128.8.0esr-1~deb12u1128.8.0esr-1
debian/thunderbird<=1:115.12.0-1~deb11u1, <=1:128.5.0esr-1~deb12u1
1:128.8.0esr-1~deb11u11:128.8.0esr-1~deb12u11:128.8.0esr-1
Mozilla Thunderbird<128.8
128.8
Mozilla Firefox<128.8.0
Mozilla Firefox<136.0
Mozilla Thunderbird<128.8.0
Mozilla Thunderbird>=129.0<136.0
Event History
Mar 4, 2025
CVE Published
via Mozilla·12:00 AM
CVE Published
via MITRE·01:31 PM
Data Sourced
via MITRE·01:31 PM
Description
Data Sourced
via Red Hat·02:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·02:15 PM
Description
Data Sourced
via NVD·02:15 PM
SeverityWeaknessAffected Software
Mar 10, 2025
Data Sourced
via Ubuntu·04:52 PM
RemedyDescriptionSeverityAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-1935?
CVE-2025-1935 is considered a medium severity vulnerability due to its potential to manipulate user settings.
2
How do I fix CVE-2025-1935?
To resolve CVE-2025-1935, update your Firefox to version 136 or Firefox ESR to version 128.8.
3
Which versions of Firefox are affected by CVE-2025-1935?
CVE-2025-1935 affects Firefox versions prior to 136 and Firefox ESR versions prior to 128.8.
4
What type of attack does CVE-2025-1935 represent?
CVE-2025-1935 represents a social engineering attack that can change the default URL protocol handler.
5
Is CVE-2025-1935 restricted to specific operating systems?
CVE-2025-1935 affects the Firefox browser on multiple operating systems including Windows, macOS, and Linux.