CVE-2025-23109: Address bar spoofing on iOS using long hostnames
Published Jan 10, 2025
·Updated
Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address
Affected Software
3 affected components
All of the following
Mozilla Firefox=134
Apple iOS
Mozilla Firefox Iphone Os<134.0
Event History
Jan 10, 2025
CVE Published
via Mozilla·12:00 AM
Jan 11, 2025
CVE Published
via MITRE·03:36 AM
Data Sourced
via MITRE·03:36 AM
Description
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-23109?
CVE-2025-23109 is categorized as a medium severity vulnerability due to its potential for spoofing website addresses.
2
How do I fix CVE-2025-23109?
To fix CVE-2025-23109, update Firefox for iOS to version 134 or later.
3
What versions of Firefox for iOS are affected by CVE-2025-23109?
CVE-2025-23109 affects Firefox for iOS versions prior to 134.
4
What is the impact of CVE-2025-23109 on users?
CVE-2025-23109 can mislead users by obscuring the actual host of a website, leading to potential phishing attacks.
5
Is there a workaround for CVE-2025-23109?
No formal workaround exists for CVE-2025-23109; updating to the latest version is the recommended solution.