External risk intelligence

Firefox Android Card Carousel Black Screen Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2025-11717

This vulnerability affects the visual rendering of the Firefox application UI on Android during app switching. It is a client-side, local interface issue requiring physical access to the device and is not a network-reachable service or internet-facing endpoint.

Information Disclosure

Mozilla Firefox

before 144.0

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This issue involves a visual rendering flaw in Firefox on Android, where switching between apps can display a black screen if a password screen was recently active, potentially exposing sensitive information. The primary concern is to confirm if this specific exposure is relevant to our environment.

  • Password screen visibility issue in Firefox.
  • Potential for sensitive data exposure.
  • Confirm relevance and exposure to our systems.

Attack Path

How an attacker could exploit the issue

An attacker could potentially trick a user into viewing a black screen in Firefox on Android, which previously would have shown a password screen. This occurs when switching between apps after using a password-related screen. The vulnerability could lead to sensitive information being exposed.

  • Entry condition: User interaction with a password screen.
  • Trigger point: Switching between Android apps.
  • Resulting risk: Sensitive information may be exposed.

Live Threat

Current exploitation, exposure, and threat context

When switching between Android applications, Firefox may display a black screen instead of the expected content when a password-related screen was previously active. This can occur when the password edit screen was the last active screen before app switching, and the issue has been fixed in later versions of Firefox.

  • Password edit screen data.
  • App switching with password screen.
  • Display of sensitive screen content.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects the Firefox application on Android devices. Application owners or platform teams responsible for managing mobile applications should investigate its presence. The first practical step is to identify all Android devices running affected versions of Firefox, confirm if this visual glitch presents a business risk, and then coordinate with the vendor or plan for an update during a suitable maintenance window.

  • Confirm Firefox ownership on Android assets.
  • Verify if affected Firefox versions are in use.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Firefox for Android?

Firefox for Android is a mobile web browser developed by Mozilla. Users rely on it to navigate the internet, manage bookmarks, and store sensitive data like saved passwords. This browser includes security features to protect user information, but bugs in its interface can occasionally disrupt how the app displays sensitive screens when managing multiple active applications.

What does CVE-2025-11717 mean by information exposure?

This vulnerability falls under the weakness class CWE-200, which involves the improper exposure of sensitive information. In this specific case, it refers to a flaw where the browser might inadvertently show or fail to properly hide a password-related screen during transitions, potentially making data visible when it should have been protected from view by the application's interface.

How is this vulnerability triggered?

The issue is triggered specifically by the action of switching between open Android applications while the browser's password-related screen was the last active item. It does not trigger during normal web browsing or when using other non-sensitive browser features. If a password screen was not the last thing viewed before multitasking, the specific display behavior associated with this flaw is not triggered.

Do I need to worry about this if I use Firefox on my phone?

According to Halo Surface Signal, this is a client-side interface issue. It is not an internet-facing vulnerability or a network-reachable service. Because it requires physical access to your specific device and interaction with the app's visual transition, the risk is localized to the handset rather than being an issue that could be exploited remotely across the network.

When should I update Firefox to fix this?

If you are using a version of Firefox for Android earlier than 144, you should update the application to the latest version available in your app store. The first practical step is to check your browser's current version number in its settings menu. Applying the update ensures that the rendering logic for the app's card carousel is corrected, closing the gap that allows for this visual information exposure.

References