CVE-2025-3029: URL Bar Spoofing via non-BMP Unicode characters
A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-3029?
CVE-2025-3029 has been classified as a high severity vulnerability due to the risk of spoofing attacks.
How can I fix CVE-2025-3029?
To fix CVE-2025-3029, update your Mozilla Thunderbird or Firefox to the latest version beyond the vulnerable releases.
What versions of software are affected by CVE-2025-3029?
CVE-2025-3029 affects Thunderbird versions prior to 137, Thunderbird ESR versions prior to 128.9, Firefox versions prior to 137, and Firefox ESR versions prior to 128.9.
What type of attack does CVE-2025-3029 facilitate?
CVE-2025-3029 facilitates potential spoofing attacks by allowing crafted URLs to hide the true origin of a page.
Who is the vendor for CVE-2025-3029?
The vendor for CVE-2025-3029 is Mozilla, which produces both Thunderbird and Firefox.