CVE-2025-23108: Firefox Mobile iOS Full Address Bar Spoof Using Open in New Tab and Javascript URI
Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefox for iOSto a version that resolves this vulnerability.Fixed in 134
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23108?
CVE-2025-23108 is a high severity vulnerability due to its ability to spoof URLs via malicious scripts.
How do I fix CVE-2025-23108?
To fix CVE-2025-23108, update your Firefox iOS client to the latest version provided by Mozilla.
Who is affected by CVE-2025-23108?
CVE-2025-23108 affects users of Mozilla Firefox version 134 running on Apple iOS.
What happens if I exploit CVE-2025-23108?
Exploiting CVE-2025-23108 can allow a malicious script to spoof the URL of a new tab, potentially leading to phishing attacks.
When was CVE-2025-23108 discovered?
CVE-2025-23108 was reported in 2025 as a vulnerability affecting the Firefox iOS client.