CVE-2025-54144: Internal Firefox open-text URL scheme allowed loading of arbitrary URLs
The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if a user was tricked into clicking a link
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-54144?
CVE-2025-54144 has been assessed with a high severity rating due to its potential to allow attackers to redirect users to malicious sites.
How do I fix CVE-2025-54144?
To resolve CVE-2025-54144, users should update their Mozilla Firefox to the latest version that addresses this vulnerability.
Which versions of software are affected by CVE-2025-54144?
CVE-2025-54144 specifically affects Mozilla Firefox version 141 and potentially related software within the Apple iOS environment.
What type of attack does CVE-2025-54144 facilitate?
CVE-2025-54144 could facilitate phishing attacks by tricking users into clicking links that direct them to unintended URLs.
Is there a workaround for CVE-2025-54144?
While upgrading is the best fix, users can avoid potential exploitation of CVE-2025-54144 by being cautious of suspicious links until the issue is resolved.