---
id: CVE-2025-1939
title: Android apps can load web pages using the Custom Tabs feature
summary: >-
  Android apps can load web pages using the Custom Tabs feature. This feature
  supports a transition animation that could have been used to trick a user into
  granting sensitive permissions by hiding what the user was actually clicking.
  This…
severity: low
cvss: 3.9
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'
cwe:
  - CWE-359
vendor: mozilla
product: firefox
affected:
  - firefox < 136.0
patched:
  - firefox 136.0
published: '2025-03-04'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T19:10:01.007'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-1939'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1928334'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-14/'
    label: security@mozilla.org
  - url: 'https://taptrap.click'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00187
epssPercentile: 0.07515
ingestedAt: '2026-09-30T19:21:07.229Z'
---

## Overview

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability was fixed in Firefox 136.

## Affected

- `firefox < 136.0`

## Remediation

Upgrade past the affected range:

- `firefox 136.0`
