Address Bar Spoofing on Mozilla Firefox (CVE-2025-0244)
CVSS SCORE: 5.3 Medium
BACKGROUND
A security vulnerability has been identified in Mozilla Firefox that poses a serious threat to users on Android devices.
The vulnerability is classified as concerning because it involves a clickjacking issue, where an attacker can manipulate the user interface to spoof the address bar when redirecting to an invalid protocol scheme.
This issue could potentially mislead users into believing they are interacting with a legitimate site, creating an opportunity for phishing attacks.
IMPACT
- An attacker may spoof the address bar.
- This could potentially lead to phishing attacks or other forms of social engineering.
It may result in the exposure of sensitive information or unauthorized account access.
AFFECTED PRODUCTS
All versions of Mozilla Firefox prior to 134.
Note: This issue only affected Android operating systems. Other operating systems are unaffected.
RECOMMENDATIONS
Users are strongly advised to upgrade to Mozilla Firefox version 134 or later to mitigate this vulnerability.
REFERENCES
https://nvd.nist.gov/vuln/detail/CVE-2025-0244
https://www.mozilla.org/en-US/security/advisories/mfsa2025-01/
https://feedly.com/cve/CVE-2025-0244