First published: Tue Jan 07 2025(Updated: )
When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 134.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <134 | 134 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-0244 is considered a moderate severity vulnerability affecting Firefox versions prior to 134.
To fix CVE-2025-0244, update your Firefox browser to version 134 or later.
Only users of Mozilla Firefox on Android operating systems are affected by CVE-2025-0244.
Yes, CVE-2025-0244 can be exploited remotely by an attacker through malformed URL redirects.
If not mitigated, CVE-2025-0244 could allow an attacker to spoof the address bar, potentially misleading users.