Skip to main content

Address Bar Spoofing on Mozilla Firefox (CVE-2025-0244)

CVSS SCORE: 5.3 Medium

BACKGROUND 

A security vulnerability has been identified in Mozilla Firefox that poses a serious threat to users on Android devices.  

The vulnerability is classified as concerning because it involves a clickjacking issue, where an attacker can manipulate the user interface to spoof the address bar when redirecting to an invalid protocol scheme.  

This issue could potentially mislead users into believing they are interacting with a legitimate site, creating an opportunity for phishing attacks.


IMPACT

  • An attacker may spoof the address bar.
  • This could potentially lead to phishing attacks or other forms of social engineering. 
  • It may result in the exposure of sensitive information or unauthorized account access. 
     

    AFFECTED PRODUCTS

    All versions of Mozilla Firefox prior to 134.

    Note: This issue only affected Android operating systems. Other operating systems are unaffected.
     

    RECOMMENDATIONS


    Users are strongly advised to upgrade to Mozilla Firefox version 134 or later to mitigate this vulnerability.
     

    REFERENCES

https://nvd.nist.gov/vuln/detail/CVE-2025-0244

https://www.mozilla.org/en-US/security/advisories/mfsa2025-01/

https://feedly.com/cve/CVE-2025-0244

 

About

Brunei Computer Emergency Response Team (BruCERT) was established in 2004 as the national and government CERT to deal with computer-related and internet-related security incidents in Negara Brunei Darussalam.