CVE-2025-27424: Firefox Mobile iOS Address Bar Spoof Using Server-Side Redirect to non-http Scheme
Published Feb 24, 2025
·Updated
Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page
Affected Software
5 affected components
All of the following
Mozilla Firefox=136
Apple iOS and iPadOS
Mozilla Firefox for iOS<136
All of the following
Mozilla Firefox<136.0
iPhone OS
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
firefox/iosto a version that resolves this vulnerability.Fixed in 136
Event History
Feb 24, 2025
CVE Published
via Mozilla·12:00 AM
Mar 4, 2025
CVE Published
via MITRE·01:31 PM
Data Sourced
via MITRE·01:31 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-27424?
CVE-2025-27424 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2025-27424?
To fix CVE-2025-27424, update Firefox for iOS to version 136 or later.
3
What types of devices are affected by CVE-2025-27424?
CVE-2025-27424 affects the Firefox browser on iOS devices.
4
What can happen if CVE-2025-27424 is exploited?
Exploiting CVE-2025-27424 can lead to the spoofing of a website address, potentially redirecting users to malicious pages.
5
Which versions of Firefox for iOS are vulnerable to CVE-2025-27424?
All versions of Firefox for iOS prior to version 136 are vulnerable to CVE-2025-27424.