Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134.
History

Mon, 13 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 11 Jan 2025 03:45:00 +0000

Type Values Removed Values Added
Description Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2025-01-11T03:36:53.989Z

Updated: 2025-01-13T17:46:18.921Z

Reserved: 2025-01-10T21:00:17.659Z

Link: CVE-2025-23108

cve-icon Vulnrichment

Updated: 2025-01-13T17:46:08.182Z

cve-icon NVD

Status : Received

Published: 2025-01-11T04:15:06.280

Modified: 2025-01-13T18:15:22.680

Link: CVE-2025-23108

cve-icon Redhat

No data.