URL Truncation Vulnerability in Mozilla Firefox
CVE-2025-3859

6.1MEDIUM

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
30 April 2025

What is CVE-2025-3859?

A vulnerability exists in Mozilla Firefox that allows websites to exploit URL truncation behavior. This can mislead users by causing the browser's location view to truncate long URLs, making it appear as though users are on a different or legitimate webpage. This can lead to phishing attempts as malicious actors may trick users into believing they are visiting trusted domains.

Affected Version(s)

Focus < 138

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

James Lee
.
CVE-2025-3859 : URL Truncation Vulnerability in Mozilla Firefox