CVE-2025-27426: Firefox Mobile iOS Full Address Bar Spoof Using Server-Side Redirect to internal error page
Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefox for iOSto a version that resolves this vulnerability.Fixed in 136
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-27426?
CVE-2025-27426 is classified as a medium severity vulnerability due to its potential for causing user confusion and spoofing attacks.
How do I fix CVE-2025-27426?
To mitigate CVE-2025-27426, update to the latest version of Firefox for iOS that is above version 136.
Who is affected by CVE-2025-27426?
CVE-2025-27426 affects users of Firefox for iOS versions below 136.
What type of attack can occur due to CVE-2025-27426?
CVE-2025-27426 can be exploited through malicious websites that redirect users to internal error pages, leading to potential URL spoofing.
What platforms are impacted by CVE-2025-27426?
CVE-2025-27426 specifically impacts Firefox for iOS running on Apple iOS, iPadOS, and watchOS.