Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mozilla
Mozilla firefox |
|
CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:* | |
Vendors & Products |
Mozilla
Mozilla firefox |
Mon, 13 Jan 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Sat, 11 Jan 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134. | |
References |
|

Status: PUBLISHED
Assigner: mozilla
Published: 2025-01-11T03:36:53.989Z
Updated: 2025-01-13T17:46:18.921Z
Reserved: 2025-01-10T21:00:17.659Z
Link: CVE-2025-23108

Updated: 2025-01-13T17:46:08.182Z

Status : Analyzed
Published: 2025-01-11T04:15:06.280
Modified: 2025-04-03T18:58:00.940
Link: CVE-2025-23108

No data.