CVE-2025-5020: Links using non-HTTP schemes opened from other apps such as Safari could have allowed spoofing of website addresses
Published May 20, 2025
·Updated
Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website addresses if the URLs utilized non-HTTP schemes used internally by the Firefox iOS client
Affected Software
4 affected components
Mozilla Firefox for iOS<139
All of the following
Mozilla Firefox=139
Apple iOS
Mozilla Firefox Iphone Os<139.0
Event History
May 20, 2025
CVE Published
via Mozilla·12:00 AM
May 21, 2025
CVE Published
via MITRE·05:18 PM
Data Sourced
via MITRE·05:18 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-5020?
CVE-2025-5020 has been classified as a medium severity vulnerability due to the potential for spoofed website addresses.
2
How do I fix CVE-2025-5020?
To mitigate CVE-2025-5020, update Firefox for iOS to version 139 or higher.
3
What types of attacks are possible with CVE-2025-5020?
CVE-2025-5020 allows attackers to spoof website addresses through maliciously-crafted URLs.
4
Which versions of Firefox for iOS are affected by CVE-2025-5020?
CVE-2025-5020 affects all versions of Firefox for iOS prior to version 139.
5
What should users do if they are using an affected version of Firefox for iOS?
Users should immediately update to Firefox for iOS version 139 or newer to avoid exploitation of CVE-2025-5020.