CVE-2025-8364: Address bar spoofing using an blob URI on Firefox for Android
A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. Note: This issue only affected Android operating systems. Other operating systems are unaffected.. This vulnerability was fixed in Firefox 141.
Other sources
A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack.Note: This issue only affected Android operating systems. Other operating systems are unaffected.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-8364?
CVE-2025-8364 has been classified as a high severity vulnerability due to its potential to facilitate spoofing attacks.
How do I fix CVE-2025-8364?
To mitigate CVE-2025-8364, users should upgrade to Mozilla Firefox version 142 or later, which addresses the issue.
Who is affected by CVE-2025-8364?
CVE-2025-8364 specifically affects users of Mozilla Firefox on Android operating systems.
What type of attack is associated with CVE-2025-8364?
CVE-2025-8364 is associated with potential spoofing attacks that could mislead users about the true origin of a page.
Is CVE-2025-8364 limited to Firefox version 141?
Yes, CVE-2025-8364 only affects Mozilla Firefox version 141 and earlier on Android devices.