PT-2025-41908 · Mozilla+1 · Firefox+2
Published
2025-10-14
·
Updated
2026-04-15
·
CVE-2025-11720
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 144
Firefox Focus versions prior to 144
Description
The user interface for the Android custom tab feature in Firefox and Firefox Focus displayed only the "site" loaded, and not the complete hostname. This allowed user-supplied content hosted on a subdomain to mislead users into believing it originated from a different subdomain of the same site.
Recommendations
Update Firefox to version 144 or later.
Update Firefox Focus to version 144 or later.
Fix
UI Misrepresentation of Critical Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Firefox
Firefox Focus