Description
Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability was fixed in Firefox for iOS 134.
Published: 2025-01-11
Score: 4.3 Medium
EPSS: 1.4% Low
KEV: No
Impact: URL spoofing via JavaScript links
Action: Update Browser
AI Analysis

Impact

Opening JavaScript links in a new tab by long‑pressing a link in Firefox for iOS lets a web page cause the browser to display a falsified address bar for the new tab. The displayed URL can be different from the actual script location, enabling a malicious site to trick users into believing they are viewing a legitimate page while executing harmful code. The weakness is a web‑UI input flaw (CWE‑79).

Affected Systems

Mozilla Firefox for iOS before version 134 is affected. The issue was fixed in Firefox iOS 134 and later releases, so any device running older builds of the mobile browser is vulnerable.

Risk and Exploitability

The vulnerability’s CVSS score of 4.3 indicates moderate impact, and the EPSS score of less than 1% suggests very low current exploitation probability. It is not listed in CISA’s KEV. The likely attack vector is a user interacting with a malicious link; the attacker needs only to host a JavaScript URL and ensure the victim long‑presses it in Firefox iOS, so the risk is limited to users who employ this interaction pattern.

Generated by OpenCVE AI on April 20, 2026 at 23:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox for iOS to version 134 or later, which includes the fix that prevents JavaScript URLs from spoofing the address bar.
  • In the intervening period, disable JavaScript in the browser’s settings or use a content‑blocking feature to block execution of JavaScript links until the update can be applied.
  • Refrain from long‑pressing JavaScript URLs; instead, tap them normally or validate the destination URL before interacting with it.

Generated by OpenCVE AI on April 20, 2026 at 23:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3122 Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134.
History

Mon, 13 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134. Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability was fixed in Firefox for iOS 134.
Title Firefox Mobile iOS Full Address Bar Spoof Using Open in New Tab and Javascript URI

Thu, 03 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*
Vendors & Products Mozilla
Mozilla firefox

Mon, 13 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 11 Jan 2025 03:45:00 +0000

Type Values Removed Values Added
Description Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-05-20T14:29:26.729Z

Reserved: 2025-01-10T21:00:17.659Z

Link: CVE-2025-23108

cve-icon Vulnrichment

Updated: 2025-01-13T17:46:08.182Z

cve-icon NVD

Status : Modified

Published: 2025-01-11T04:15:06.280

Modified: 2026-04-13T15:16:54.423

Link: CVE-2025-23108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T00:00:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')