First published: Fri Jan 10 2025(Updated: )
Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Mozilla Firefox | =134 | |
Apple iOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23108 is a high severity vulnerability due to its ability to spoof URLs via malicious scripts.
To fix CVE-2025-23108, update your Firefox iOS client to the latest version provided by Mozilla.
CVE-2025-23108 affects users of Mozilla Firefox version 134 running on Apple iOS.
Exploiting CVE-2025-23108 can allow a malicious script to spoof the URL of a new tab, potentially leading to phishing attacks.
CVE-2025-23108 was reported in 2025 as a vulnerability affecting the Firefox iOS client.