CVE-2025-23108

Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*

History

03 Apr 2025, 18:58

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1933172 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1933172 - Issue Tracking, Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2025-06/ - () https://www.mozilla.org/security/advisories/mfsa2025-06/ - Vendor Advisory
First Time Mozilla firefox
Mozilla
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*

13 Jan 2025, 18:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
Summary
  • (es) Abrir enlaces de Javascript en una nueva pestaña manteniendo pulsada la tecla en el cliente iOS de Firefox podría provocar que un script malicioso falsifique la URL de la nueva pestaña. Esta vulnerabilidad afecta a Firefox para iOS &lt; 134.

11 Jan 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-11 04:15

Updated : 2025-04-03 18:58


NVD link : CVE-2025-23108

Mitre link : CVE-2025-23108

CVE.ORG link : CVE-2025-23108


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')