CVE-2025-10530

EUVD-2025-29556
Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
mozillaCNA
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 20.05%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
mozillafirefox
𝑥
< 143.0
CNA
mozillathunderbird
𝑥
< 143.0
CNA
Debian logo
Debian Releases
Debian Product
Codename
firefox
sid
156.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
jammy
not-affected
noble
not-affected
plucky
not-affected
questing
not-affected
thunderbird
jammy
not-affected
noble
not-affected
plucky
not-affected
questing
not-affected