Description
Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox ESR 140.2.
Published: 2025-08-19
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Address Bar spoofing
Action: Immediate update
AI Analysis

Impact

The vulnerability allows an attacker to manipulate the text displayed in the browser’s address bar so that it misleads the user into believing they are interacting with a trusted domain. This can facilitate phishing or social‑engineering attacks, compromising the confidentiality of the user’s actions without requiring code execution. The weakness is listed as CWE-451, implicating Impersonation.

Affected Systems

Mozilla Firefox is affected, including the standard release and the ESR channel. Any installation of Firefox prior to version 142, and Firefox ESR prior to 140.2, is vulnerable. Later releases contain the fix.

Risk and Exploitability

The CVSS score of 6.5 reflects moderate severity. EPSS indicates a less than 1% chance of exploitation, and the vulnerability is not yet in the CISA KEV catalog. The likely attack vector involves a malicious website or link that, by forcing the address bar to display a spoofed URL, tricks a user into trusting the site. Successful exploitation depends on user interaction and the user’s willingness to trust the altered address bar.

Generated by OpenCVE AI on April 20, 2026 at 16:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox to version 142 or later, or Firefox ESR 140.2 or later, to apply the official fix.
  • If an upgrade is not possible at the moment, install the latest security update provided by Mozilla’s update service to reduce exposure.
  • Until the update is applied, avoid interacting with unfamiliar websites and verify the address bar content before entering sensitive information.

Generated by OpenCVE AI on April 20, 2026 at 16:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-25240 Spoofing issue in the Address Bar component. This vulnerability affects Firefox < 142 and Firefox ESR < 140.2.
History

Mon, 13 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Spoofing issue in the Address Bar component. This vulnerability affects Firefox < 142 and Firefox ESR < 140.2. Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox ESR 140.2.

Thu, 30 Oct 2025 16:30:00 +0000

Type Values Removed Values Added
Title firefox: Spoofing issue in the Address Bar component Spoofing issue in the Address Bar component

Fri, 22 Aug 2025 00:15:00 +0000

Type Values Removed Values Added
Title firefox: Spoofing issue in the Address Bar component
References
Metrics threat_severity

None

threat_severity

Low


Thu, 21 Aug 2025 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*

Thu, 21 Aug 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Mozilla firefox Esr
Vendors & Products Mozilla
Mozilla firefox
Mozilla firefox Esr

Wed, 20 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 19 Aug 2025 20:45:00 +0000

Type Values Removed Values Added
Description Spoofing issue in the Address Bar component. This vulnerability affects Firefox < 142 and Firefox ESR < 140.2.
References

Subscriptions

Mozilla Firefox Firefox Esr
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-04-13T14:28:39.668Z

Reserved: 2025-08-19T15:56:04.756Z

Link: CVE-2025-9183

cve-icon Vulnrichment

Updated: 2025-08-20T14:04:31.545Z

cve-icon NVD

Status : Modified

Published: 2025-08-19T21:15:30.777

Modified: 2026-04-13T15:17:14.140

Link: CVE-2025-9183

cve-icon Redhat

Severity : Low

Publid Date: 2025-08-19T20:33:57Z

Links: CVE-2025-9183 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-20T17:00:12Z

Weaknesses