CVE-2025-11718: Address bar could be spoofed on Android using visibilitychange
When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11718?
The severity of CVE-2025-11718 is classified as high due to the potential for user deception through a fake address bar.
How do I fix CVE-2025-11718?
To fix CVE-2025-11718, update your Mozilla Firefox to version 145 or later as it contains the necessary patches.
What are the potential impacts of CVE-2025-11718?
CVE-2025-11718 can lead to phishing attacks, where users may be misled into entering sensitive information into a fake address bar.
Is my version of Firefox vulnerable to CVE-2025-11718?
If you are using Mozilla Firefox version 144 or lower, your version is vulnerable to CVE-2025-11718.
What should I do if I encounter a suspicious address bar while using Firefox on Android?
If you encounter a suspicious address bar in Firefox on Android, do not enter any information and update Firefox immediately.