CVE-2025-9186: Spoofing issue in the Address Bar component of Firefox Focus for Android
Published Aug 19, 2025
·Updated
Spoofing issue in the Address Bar component of Firefox Focus for Android.
Affected Software
3 affected componentsFixes available
Mozilla Firefox Focus<142
Mozilla Firefox<142.0
Mozilla Firefox<142
142
Event History
Aug 19, 2025
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·08:33 PM
Data Sourced
via MITRE·08:33 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 27, 57989
Event
via FIRST·11:43 PM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-9186?
CVE-2025-9186 has a moderate severity level due to its potential to allow spoofing in the Address Bar component.
2
How do I fix CVE-2025-9186?
To fix CVE-2025-9186, update Firefox Focus to version 142 or later.
3
What impact does CVE-2025-9186 have on users?
CVE-2025-9186 could allow malicious websites to spoof trusted sites in the Address Bar, potentially leading to phishing attacks.
4
Which versions of Firefox Focus are affected by CVE-2025-9186?
CVE-2025-9186 affects all versions of Firefox Focus prior to version 142.
5
Is CVE-2025-9186 present in desktop versions of Firefox?
CVE-2025-9186 is specifically a vulnerability in the mobile version, Firefox Focus for Android, and does not affect desktop versions.