VYPR
Medium severity4.3NVD Advisory· Published Mar 4, 2025· Updated Apr 13, 2026

CVE-2025-1935

CVE-2025-1935

Description

A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A web page could trick a user into setting that site as the default handler for a custom URL protocol via clickjacking of permission prompts.

A clickjacking vulnerability exists in the handling of registerProtocolHandler permission prompts in Mozilla products. A malicious web page could trick a user into setting that site as the default handler for a custom URL protocol by overlaying transparent elements on the permission prompt, causing the user to inadvertently grant approval [2].

Exploitation requires user interaction: the attacker crafts a page that hides the actual permission dialog behind seemingly innocuous content. When the user clicks on what appears to be a legitimate element, the click is actually on the "Allow" button of the permission prompt, thereby granting the malicious site default handler status for a custom protocol [2].

Successful exploitation allows the attacker's site to intercept and handle requests for the custom URL protocol. This could be leveraged for further attacks such as phishing, stealing sensitive data, or executing arbitrary actions in the context of the protocol [1].

Mozilla addressed this vulnerability in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8 [1][3][4]. Users are advised to update their software to the latest versions to mitigate the risk.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

31

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.