#VU105323 Security features bypass in Firefox Focus for Android - CVE-2025-1941


Vulnerability identifier: #VU105323

Vulnerability risk: Low

CVSSv4.0: 0.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-1941

CWE-ID: CWE-254

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Firefox Focus for Android
Mobile applications / Apps for mobile phones

Vendor: Mozilla

Description

The vulnerability allows a remote attacker to bypass the lock screen.

The vulnerability exists due to the way notifications are handled on a locked screen. Under certain circumstances a user opt-in setting that Focus should require authentication before use can be bypassed, resulting in unauthorized access to the browser.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Firefox Focus for Android: before 136.0


External links
https://www.mozilla.org/en-US/security/advisories/mfsa2025-14/
https://bugzilla.mozilla.org/show_bug.cgi?id=1944665


Q & A

Can this vulnerability be exploited remotely?

No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability