External risk intelligence

Firefox for iOS Passkey Transport Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-55031

This vulnerability affects a client-side mobile application (Firefox for iOS). Exploitation requires the attacker to be in close physical Bluetooth proximity to the user to trigger the specific passkey transport mechanism, meaning the attack surface is not public-internet-facing or remotely reachable in a standard network sense.

Mozilla Firefox

before 142.0

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security flaw in Firefox for iOS could allow malicious websites to trick users into inadvertently logging an attacker's computer into their accounts using passkey technology. This vulnerability could enable unauthorized access to accounts if exploited.

  • Malicious links could misuse passkeys on iPhones.
  • Protects against unauthorized account access.
  • Confirm if affected users are within Bluetooth range.

Attack Path

How an attacker could exploit the issue

An attacker could create a malicious webpage that, when visited by a user, tricks the Firefox for iOS browser into passing FIDO links to the operating system. This interaction, if the attacker is within Bluetooth range, could lead to a user's passkey being used to log into the attacker's computer for the targeted account.

  • Attacker requires Bluetooth proximity.
  • Malicious page triggers passkey transport.
  • Compromised account login.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow a malicious webpage to trick a user into logging into an account with their passkey on an attacker's computer. This could occur when a user navigates to a specially crafted webpage, and the attacker is within Bluetooth range.

  • Passkeys and account access at risk.
  • User is tricked into using passkey.
  • Unauthorized account access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts client-side mobile applications, specifically Firefox and Firefox Focus on iOS. Owners of these applications and potentially the mobile device management (MDM) team should prioritize identifying affected devices. The first practical step is to determine the scope of deployment and confirm if any business-critical devices are utilizing the vulnerable versions, followed by planning coordinated updates during the next maintenance window.

  • Application owners should address this.
  • Verify all affected devices are identified.
  • Plan and coordinate updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Firefox for iOS and Firefox Focus?

These are web browsers developed by Mozilla for Apple's mobile operating system. Firefox for iOS provides a full browsing experience, while Firefox Focus is a privacy-focused browser that automatically blocks trackers. Both utilize the same underlying engine to render websites and manage web interactions, such as handling authentication requests and security protocols on iPhones and iPads.

How does CVE-2025-55031 affect passkeys?

This vulnerability is classified as CWE-601, or an open redirect-style weakness. In the context of CVE-2025-55031, it allows a malicious website to improperly pass specific FIDO links to the iOS system. By manipulating how these links are handled, the browser can trick the user's device into attempting a passkey authentication on an attacker-controlled computer instead of the intended legitimate site.

When does this passkey issue happen?

The attack requires two specific conditions. First, the user must visit a specially crafted, malicious webpage using an affected version of the browser. Second, the attacker must be physically close enough to the user’s device to establish a Bluetooth connection, as this is required to complete the passkey transport mechanism. Simply visiting a webpage without an attacker in Bluetooth range does not trigger this specific vulnerability.

Is this CVE a risk to my internet-facing servers?

No. According to Halo Surface Signal, this vulnerability is not a public-internet-facing risk. Because the attack relies on client-side mobile application behavior and requires close physical Bluetooth proximity between the victim and the attacker, it does not represent a standard remote network exploitation scenario that would target your server infrastructure.

What should I do if I use these browsers?

You should update to version 142 or later of Firefox for iOS or Firefox Focus. Start by identifying which mobile devices in your environment are running older versions. Once you have identified these instances, plan to deploy the update through your standard mobile application management processes to ensure the browser code is patched against this passkey misuse.

References