Impact
The vulnerability allows an attacker to manipulate the text displayed in the browser’s address bar so that it misleads the user into believing they are interacting with a trusted domain. This can facilitate phishing or social‑engineering attacks, compromising the confidentiality of the user’s actions without requiring code execution. The weakness is listed as CWE-451, implicating Impersonation.
Affected Systems
Mozilla Firefox is affected, including the standard release and the ESR channel. Any installation of Firefox prior to version 142, and Firefox ESR prior to 140.2, is vulnerable. Later releases contain the fix.
Risk and Exploitability
The CVSS score of 6.5 reflects moderate severity. EPSS indicates a less than 1% chance of exploitation, and the vulnerability is not yet in the CISA KEV catalog. The likely attack vector involves a malicious website or link that, by forcing the address bar to display a spoofed URL, tricks a user into trusting the site. Successful exploitation depends on user interaction and the user’s willingness to trust the altered address bar.
OpenCVE Enrichment
EUVD