← back
CVE-2025-0244mediumCWE-601

Address bar spoofing using an invalid protocol scheme on Firefox for Android

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.3epss 6.5%
exploitation probability
6.5%top 7% of all CVEs
observed exploitation
nono source reports it
When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 134.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
Mozilla · Firefox