CVE-2025-23109

Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address. This vulnerability was fixed in Firefox for iOS 134.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*

History

13 Apr 2026, 15:16

Type Values Removed Values Added
Summary (en) Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address This vulnerability affects Firefox for iOS < 134. (en) Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address. This vulnerability was fixed in Firefox for iOS 134.

03 Apr 2025, 18:52

Type Values Removed Values Added
First Time Mozilla firefox
Mozilla
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1419275 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1419275 - Issue Tracking, Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2025-06/ - () https://www.mozilla.org/security/advisories/mfsa2025-06/ - Vendor Advisory

13 Jan 2025, 18:15

Type Values Removed Values Added
Summary
  • (es) Los nombres de host largos en las URL podrían aprovecharse para ocultar el host real del sitio web o falsificar la dirección del sitio web. Esta vulnerabilidad afecta a Firefox para iOS &lt; 134.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-346

11 Jan 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-11 04:15

Updated : 2026-04-13 15:16


NVD link : CVE-2025-23109

Mitre link : CVE-2025-23109

CVE.ORG link : CVE-2025-23109


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-346

Origin Validation Error