Horizon Alert
Summary of the vulnerability and why it matters
A security flaw in Firefox for iOS could allow malicious websites to trick users into inadvertently logging an attacker's computer into their accounts using passkey technology. This vulnerability could enable unauthorized access to accounts if exploited.
- Malicious links could misuse passkeys on iPhones.
- Protects against unauthorized account access.
- Confirm if affected users are within Bluetooth range.
Attack Path
How an attacker could exploit the issue
An attacker could create a malicious webpage that, when visited by a user, tricks the Firefox for iOS browser into passing FIDO links to the operating system. This interaction, if the attacker is within Bluetooth range, could lead to a user's passkey being used to log into the attacker's computer for the targeted account.
- Attacker requires Bluetooth proximity.
- Malicious page triggers passkey transport.
- Compromised account login.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow a malicious webpage to trick a user into logging into an account with their passkey on an attacker's computer. This could occur when a user navigates to a specially crafted webpage, and the attacker is within Bluetooth range.
- Passkeys and account access at risk.
- User is tricked into using passkey.
- Unauthorized account access.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability impacts client-side mobile applications, specifically Firefox and Firefox Focus on iOS. Owners of these applications and potentially the mobile device management (MDM) team should prioritize identifying affected devices. The first practical step is to determine the scope of deployment and confirm if any business-critical devices are utilizing the vulnerable versions, followed by planning coordinated updates during the next maintenance window.
- Application owners should address this.
- Verify all affected devices are identified.
- Plan and coordinate updates.