Description
When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event. This vulnerability was fixed in Firefox 144.
Published: 2025-10-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: User deception via spoofed address bar
Action: Apply Patch
AI Analysis

Impact

When the address bar in Firefox on Android hides because the user scrolls, a malicious web page can trigger the visibilitychange event to detect the hide, and then create a fake address bar overlay that looks like the real one. The fake bar can display arbitrary domain names or URLs to mislead the user into thinking they are on a trusted site, enabling phishing or other social‑engineering attacks. No code is executed; the issue is a UI deception flaw that undermines user trust.

Affected Systems

This flaw affects the Mozilla Firefox browser on Android devices, specifically all releases prior to version 144. It also relies on the Android operating system’s handling of the visibilitychange event, so any device running Android that has an unfixed version of Firefox is susceptible. The movement of the address bar during scrolling is the trigger that the malicious page exploits.

Risk and Exploitability

The CVSS score of 6.5 classifies the vulnerability as a moderate severity compromise of user interface integrity. The EPSS score of less than 1% indicates a very low likelihood of widespread exploitation at present, and the flaw is not currently catalogued in the CISA KEV list. An attacker needs only a malicious webpage loaded in the victim’s Firefox browser on an Android device; no additional privileges or network access are required. Once the page gains visibilitychange access it can overlay the spoofed bar immediately, making the attack surface narrow but readily reproducible in a typical browsing session.

Generated by OpenCVE AI on April 20, 2026 at 17:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 144 or later on all Android devices that use the browser.
  • Enable automatic updates for Firefox and for Android to receive future security fixes promptly.
  • Verify that the device’s Android version is current, as newer OS releases incorporate additional security enhancements that complement the browser patch.

Generated by OpenCVE AI on April 20, 2026 at 17:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event This vulnerability affects Firefox < 144. When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event. This vulnerability was fixed in Firefox 144.

Thu, 30 Oct 2025 16:30:00 +0000

Type Values Removed Values Added
Title Address bar could be spoofed on Android using visibilitychange

Wed, 15 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Mozilla
Mozilla firefox
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google
Google android
Mozilla
Mozilla firefox

Wed, 15 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Oct 2025 13:00:00 +0000

Type Values Removed Values Added
Description When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event This vulnerability affects Firefox < 144.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-04-13T14:31:20.787Z

Reserved: 2025-10-13T19:50:18.353Z

Link: CVE-2025-11718

cve-icon Vulnrichment

Updated: 2025-10-15T13:20:21.053Z

cve-icon NVD

Status : Modified

Published: 2025-10-14T13:15:38.150

Modified: 2026-04-13T15:16:41.083

Link: CVE-2025-11718

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-20T18:00:11Z

Weaknesses