External risk intelligence

Firefox iOS QR Scanner Malicious Link Opening Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2025-54145

This vulnerability is client-side, requiring the user to physically interact with the device by scanning a malicious QR code. It is not a service or internet-facing application that can be reached remotely by an attacker, making public network exposure of this specific attack surface unlikely.

Mozilla Firefox

before 141.0

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified that could allow malicious websites to open automatically through a QR scanner if users are tricked into scanning a malicious link. This issue affects Firefox on iOS and has been resolved in a recent update. The primary concern is confirming whether this specific technology is in use within our organization and if there is any exposure.

  • Malicious QR codes could open unwanted websites.
  • User interaction is required for exploitation.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could trick a user into scanning a malicious QR code, which would then leverage a vulnerability in the QR scanner to open arbitrary websites. This could lead to sensitive information being exposed or further malicious actions being initiated on the user's device.

  • User scans a malicious QR code.
  • QR scanner opens a malicious URL.
  • Sensitive data exposure and further compromise.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, arbitrary websites could be opened when a user is tricked into scanning a malicious link that uses Firefox's open-text URL scheme.

  • Malicious websites could be opened.
  • User scans a malicious QR code.
  • Arbitrary website access.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-World Ownership

This vulnerability affects the Firefox mobile application, meaning Platform or Mobile Application Owners are likely responsible for remediation. The initial priority is to identify all devices running the affected version of Firefox for iOS, determine if these devices are business-critical, and confirm the existence of any compensating controls or user education that may mitigate the risk of users scanning malicious QR codes. Once exposure is understood, a remediation plan, likely involving coordinating with the Mobile Application or Security Team for deployment of updated application versions, should be developed.

  • Own by: Mobile Application Owners.
  • Verify first: Affected device exposure and criticality.
  • Action to follow: Plan and coordinate updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Firefox for iOS?

Firefox for iOS is a mobile web browser developed by Mozilla specifically for Apple's iPhone operating system. It provides users with tools for private web browsing, cross-device synchronization of bookmarks and passwords, and integrated features like a QR code scanner to quickly navigate to URLs.

What does CWE-601 mean for CVE-2025-54145?

CWE-601 refers to a URL Redirection to Untrusted Site vulnerability, often called an Open Redirect. In this specific case, the flaw in the Firefox for iOS QR scanner allows the application to be tricked into navigating to an arbitrary, potentially malicious website instead of the intended destination when a user scans a link.

How does an attacker trigger this vulnerability?

An attacker triggers this by convincing a user to scan a specially crafted QR code containing a malicious link. This vulnerability does not trigger through automated network scanning or remote access; it specifically requires the user to physically interact with the device and perform the scan action.

Is my device at risk of this CVE?

Halo Surface Signal indicates that this is a client-side issue, making remote, internet-facing exploitation unlikely. Because the attack requires physical user interaction via a QR scan, it is generally less concerning than services exposed to the public internet, though individual devices running older versions remain susceptible.

How do I secure my devices against this issue?

The primary response is to update the Firefox application on all affected iOS devices to version 141 or later, as this version includes the necessary security fixes. Mobile device administrators should identify managed devices running older versions and coordinate the deployment of the latest update to ensure the QR scanner is patched.

References