Passkey Misuse Vulnerability in Firefox for iOS by Mozilla
CVE-2025-55031

9.8CRITICAL

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
19 August 2025

What is CVE-2025-55031?

A vulnerability exists in Firefox for iOS and Focus for iOS versions prior to 142, allowing malicious web pages to exploit the FIDO protocol. An attacker within Bluetooth range could potentially trick users into using their passkeys to log into an attacker's computer when attempting to access their accounts. This situation exposes users to unauthorized access, highlighting the need for enhanced security measures and vigilance while using these browsers.

Affected Version(s)

Firefox for iOS < 142

Focus for iOS < 142

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hafiizh
.