CVE-2025-55031: Passkey phishing within Bluetooth range
Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the target account.
Other sources
Malicious pages could use Focus for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the target account.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-55031?
CVE-2025-55031 has been classified with a high severity rating due to its potential to compromise user accounts via malicious web pages.
How do I fix CVE-2025-55031?
To mitigate CVE-2025-55031, users should update Firefox for iOS and Mozilla Focus to the latest version available that addresses the vulnerability.
Who is affected by CVE-2025-55031?
CVE-2025-55031 affects users of Firefox for iOS version 142 and Mozilla Focus version 142 operating on Apple iOS.
What is the exploitation method for CVE-2025-55031?
CVE-2025-55031 can be exploited by malicious pages that trick users into passing their FIDO passkeys within Bluetooth range.
What are the potential consequences of CVE-2025-55031?
The exploitation of CVE-2025-55031 can lead to unauthorized access to user accounts by allowing attackers to log in using stolen passkeys.