CVE-2025-3859: Firefox Focus elide URL allows address bar spoofing
Published Apr 21, 2025
·Updated
Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage
Affected Software
3 affected componentsFixes available
Focus Focus<138
Mozilla Focus<138
138
Mozilla Firefox Focus Iphone Os<138.0
Event History
Apr 21, 2025
CVE Published
via Mozilla·12:00 AM
Apr 30, 2025
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-3859?
CVE-2025-3859 has been classified with a medium severity rating.
2
How do I fix CVE-2025-3859?
To mitigate CVE-2025-3859, users should upgrade to Focus version 138 or later.
3
What impact does CVE-2025-3859 have on users?
CVE-2025-3859 could potentially mislead users by truncating long URLs, leading to a misconception of their webpage location.
4
Which software versions are affected by CVE-2025-3859?
CVE-2025-3859 affects Focus versions prior to 138.
5
Is there a workaround for CVE-2025-3859 before updating?
There are no specific workarounds for CVE-2025-3859, so updating is recommended to mitigate the risk.