PT-2025-22404 · Mozilla · Firefox
James Lee
·
Published
2025-05-20
·
Updated
2025-06-14
·
CVE-2025-5020
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox for iOS versions prior to 139
Description
The issue allows attackers to spoof website addresses when opening maliciously-crafted URLs in Firefox from other apps, such as Safari, if the URLs utilize non-HTTP schemes used internally by the Firefox iOS client.
Recommendations
For Firefox for iOS versions prior to 139, update to version 139 or later to resolve the issue. As a temporary workaround, consider avoiding the use of non-HTTP schemes in URLs when opening them from other apps. Restrict access to potentially malicious URLs to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firefox