CVE-2025-1941
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been b
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability was fixed in Firefox 136.
CRITICAL · CVSS 9.1
EPSS 0.00066
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules1
YARA rules0