PT-2025-3811 · Mozilla+1 · Firefox+1

James Lee

·

Published

2025-01-07

·

Updated

2025-11-19

·

CVE-2025-0246

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 134
Description When using an invalid protocol scheme, an attacker could spoof the address bar. This issue only affects Android operating systems, while other operating systems are unaffected.
Recommendations For Firefox versions prior to 134, update to version 134 or later to resolve the issue. As a temporary workaround, consider restricting the use of invalid protocol schemes to minimize the risk of exploitation.

Fix

UI Misrepresentation of Critical Information

Weakness Enumeration

Related Identifiers

ALT-PU-2025-11100
ALT-PU-2025-14599
ALT-PU-2025-1984
ALT-PU-2025-2230
BDU:2025-02405
CVE-2025-0246
OPENSUSE-SU-2025:14630-1

Affected Products

Alt Linux
Firefox