Description
The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if a user was tricked into clicking a link. This vulnerability was fixed in Firefox for iOS 141.
Published: 2025-08-19
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Open arbitrary URLs from malicious links
Action: Update Firefox
AI Analysis

Impact

Firefox for iOS uses an internal "open-text" URL scheme that, when malformed, can be exploited to load any arbitrary webpage or internal application page. This allows an attacker to deceive a user into navigating to a malicious site or executing unintended internal actions, potentially leading to phishing or compromise of user data. The weakness is classified as CWE‑601 (Open Redirect). The impact is moderate, affecting confidentiality and integrity of user sessions but not granting direct code execution.

Affected Systems

All builds of Firefox for iOS released before version 141 are affected; the vulnerability was addressed in update 141. Users must ensure they are running a patched version of the browser on iOS devices.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. EPSS is below 1%, showing a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack requires user interaction: the victim must click a link crafted by the attacker. While the risk is not high, it remains noteworthy especially when users receive unsolicited or suspicious links.

Generated by OpenCVE AI on April 20, 2026 at 16:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Firefox for iOS version 141 or later via the App Store
  • Enable automatic updates for Firefox to ensure timely receipt of security patches
  • Instruct users to be cautious of unexpected links and avoid clicking them unless the source is verified

Generated by OpenCVE AI on April 20, 2026 at 16:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-25229 The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if a user was tricked into clicking a link This vulnerability affects Firefox for iOS < 141.
History

Mon, 13 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if a user was tricked into clicking a link This vulnerability affects Firefox for iOS < 141. The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if a user was tricked into clicking a link. This vulnerability was fixed in Firefox for iOS 141.
Title Internal Firefox open-text URL scheme allowed loading of arbitrary URLs

Thu, 21 Aug 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla firefox
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*
Vendors & Products Mozilla firefox

Thu, 21 Aug 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios
Mozilla
Mozilla firefox For Ios
Vendors & Products Apple
Apple ios
Mozilla
Mozilla firefox For Ios

Wed, 20 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 19 Aug 2025 21:00:00 +0000

Type Values Removed Values Added
Description The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if a user was tricked into clicking a link This vulnerability affects Firefox for iOS < 141.
References

Subscriptions

Apple Ios
Mozilla Firefox Firefox For Ios
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-04-13T14:30:54.598Z

Reserved: 2025-07-17T02:35:52.285Z

Link: CVE-2025-54144

cve-icon Vulnrichment

Updated: 2025-08-20T14:02:45.556Z

cve-icon NVD

Status : Modified

Published: 2025-08-19T21:15:27.710

Modified: 2026-04-13T15:17:02.017

Link: CVE-2025-54144

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-20T17:00:12Z

Weaknesses