CVE-2025-11720

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability was fixed in Firefox 144.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

History

13 Apr 2026, 15:16

Type Values Removed Values Added
Summary (en) The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability affects Firefox < 144. (en) The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability was fixed in Firefox 144.

15 Oct 2025, 18:10

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
First Time Google
Google android
Mozilla firefox
Mozilla
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1979534 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1979534 - Issue Tracking, Permissions Required
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1984370 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1984370 - Issue Tracking, Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2025-81/ - () https://www.mozilla.org/security/advisories/mfsa2025-81/ - Vendor Advisory

15 Oct 2025, 14:15

Type Values Removed Values Added
CWE CWE-451
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

14 Oct 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-14 13:15

Updated : 2026-04-13 15:16


NVD link : CVE-2025-11720

Mitre link : CVE-2025-11720

CVE.ORG link : CVE-2025-11720


JSON object : View

Products Affected

google

  • android

mozilla

  • firefox
CWE
CWE-451

User Interface (UI) Misrepresentation of Critical Information