CVE-2025-55031 – Firefox for iOS Bluetooth Hybrid Passkey Transport Vulnerability

The following table lists the changes that have been made to the
CVE-2025-55031 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 19, 2025

    Action Type Old Value New Value
    Added Description Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker’s computer into the target account. This vulnerability affects Firefox for iOS < 142 and Focus for iOS < 142.
    Added Reference https://bugzilla.mozilla.org/show_bug.cgi?id=1979499
    Added Reference https://bugzilla.mozilla.org/show_bug.cgi?id=1979804
    Added Reference https://www.mozilla.org/security/advisories/mfsa2025-68/
    Added Reference https://www.mozilla.org/security/advisories/mfsa2025-69/
Share the Post:

Related Posts