Mozilla Firefox for iOS Address Bar Spoofing Vulnerability via JavaScript Links

Vulnerability

A vulnerability in Firefox for iOS versions prior to 134 allows for address bar spoofing. When JavaScript links are opened in a new tab through a long press, a malicious script can manipulate the URL displayed in the new tab's address bar.

Impact

Exploitation of this vulnerability could lead to address bar spoofing, allowing malicious scripts to deceive users about the actual URL of the page they are viewing.

Remediation

Users can upgrade to Firefox for iOS version 134 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.