First published: Tue Jan 07 2025(Updated: )
When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* *Note: This issue is a different issue from CVE-2025-0244. This vulnerability affects Firefox < 134.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <134 | 134 |
All of | ||
Firefox | <134.0 | |
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-0246 is considered a moderate severity vulnerability affecting Firefox versions below 134.
To fix CVE-2025-0246, upgrade to Mozilla Firefox version 134 or later.
CVE-2025-0246 affects users of Mozilla Firefox on Android operating systems.
CVE-2025-0246 could enable an attacker to spoof the address bar through the use of an invalid protocol scheme.
No specific workaround is recommended for CVE-2025-0246; the best solution is to update to the latest version of Firefox.