URL Spoofing Vulnerability in Firefox for iOS
CVE-2025-23108

4.3MEDIUM

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
11 January 2025

What is CVE-2025-23108?

A security vulnerability in the Firefox for iOS browser allows malicious scripts to spoof the URL of new tabs when users open JavaScript links via long-press. This issue primarily affects versions of Firefox for iOS prior to version 134, potentially misleading users and exposing them to phishing attacks. Users are encouraged to update their browsers to the latest version to mitigate the risk associated with this vulnerability.

Affected Version(s)

Firefox for iOS 134

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Renwa
.