Description
Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first. This vulnerability was fixed in Firefox for iOS 136.
Published: 2025-03-04
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Bypass of URL confirmation allows malicious site access
Action: Apply Patch
AI Analysis

Impact

A user can scan a QR code that contains a website URL and the Firefox for iOS browser will open the link without presenting the usual confirmation alert. The flaw allows an attacker to deliver malicious content or phishing pages directly through a QR code, bypassing the user’s guardrail. Based on the description, it is inferred that the attacker’s primary vector is a crafted QR code presented to a victim who is using Firefox on iOS, resulting in the automatic opening of a potentially harmful website. The vulnerability involves a weakness in the browser’s confirmation logic rather than a traditional authentication bypass.

Affected Systems

Vendors affected are Mozilla for the Firefox for iOS product. The fix was supplied in Firefox for iOS version 136, so all earlier releases are vulnerable. The issue manifests on iOS devices running the Firefox app.

Risk and Exploitability

The CVSS score of 4.3 indicates a medium severity, and the EPSS score of less than 1% shows exploitation is considered low probability. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to supply a crafted QR code to a user who scans it using Firefox on iOS; no network‑level access or additional credentials are required to trigger the bypass.

Generated by OpenCVE AI on April 20, 2026 at 20:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox for iOS version 136 or newer
  • Configure the browser to require explicit confirmation for any URL opened from a QR code
  • Monitor for suspicious QR code usage and enforce strict scanning policies

Generated by OpenCVE AI on April 20, 2026 at 20:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-7773 Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first This vulnerability affects Firefox for iOS < 136.
History

Mon, 13 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first This vulnerability affects Firefox for iOS < 136. Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first. This vulnerability was fixed in Firefox for iOS 136.
Title QR code user confirmation bypass with invalid protocol

Thu, 03 Apr 2025 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple iphone Os
Mozilla
Mozilla firefox
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple iphone Os
Mozilla
Mozilla firefox

Tue, 04 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first This vulnerability affects Firefox for iOS < 136.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-04-13T14:29:06.595Z

Reserved: 2025-02-24T20:03:31.187Z

Link: CVE-2025-27425

cve-icon Vulnrichment

Updated: 2025-03-04T15:25:46.282Z

cve-icon NVD

Status : Modified

Published: 2025-03-04T14:15:39.493

Modified: 2026-04-13T15:16:55.310

Link: CVE-2025-27425

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-20T20:45:16Z

Weaknesses