Spoofing Vulnerability in Firefox Focus for Android by Mozilla
CVE-2025-9186

6.5MEDIUM

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
19 August 2025

What is CVE-2025-9186?

A spoofing vulnerability in the Address Bar component of Firefox Focus for Android enables potential attackers to manipulate the displayed URL, misleading users about the identity of the website they are visiting. This vulnerability affects versions of Firefox Focus prior to 142, highlighting the importance of using the latest software to safeguard user data and privacy.

Affected Version(s)

Firefox < 142

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kevin Brosnan
.
CVE-2025-9186 : Spoofing Vulnerability in Firefox Focus for Android by Mozilla