Arbitrary Website Access Vulnerability in Firefox for iOS
CVE-2025-54145
9.1CRITICAL
What is CVE-2025-54145?
A vulnerability exists in Firefox for iOS versions earlier than 141 that may allow an attacker to exploit the QR scanner feature. If a user is deceived into scanning a malicious QR code, it could result in arbitrary websites being loaded through the Firefox open-text URL scheme. This poses a risk of directing users to potentially harmful sites without their consent.
Affected Version(s)
Firefox for iOS < 141