CVE-2025-23108: Firefox Mobile iOS Full Address Bar Spoof Using Open in New Tab and Javascript URI
Published Jan 10, 2025
·Updated
Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab.
Affected Software
3 affected components
All of the following
Mozilla Firefox=134
Apple iOS
Mozilla Firefox Iphone Os<134.0
Event History
Jan 10, 2025
CVE Published
via Mozilla·12:00 AM
Jan 11, 2025
CVE Published
via MITRE·03:36 AM
Data Sourced
via MITRE·03:36 AM
Description
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-23108?
CVE-2025-23108 is a high severity vulnerability due to its ability to spoof URLs via malicious scripts.
2
How do I fix CVE-2025-23108?
To fix CVE-2025-23108, update your Firefox iOS client to the latest version provided by Mozilla.
3
Who is affected by CVE-2025-23108?
CVE-2025-23108 affects users of Mozilla Firefox version 134 running on Apple iOS.
4
What happens if I exploit CVE-2025-23108?
Exploiting CVE-2025-23108 can allow a malicious script to spoof the URL of a new tab, potentially leading to phishing attacks.
5
When was CVE-2025-23108 discovered?
CVE-2025-23108 was reported in 2025 as a vulnerability affecting the Firefox iOS client.