Mozilla Firefox for iOS Address Bar Spoofing Vulnerability via Non-HTTP Redirects

Vulnerability

A vulnerability in Firefox for iOS versions prior to 136 allows for address bar spoofing. This issue arises when websites redirect to URLs using non-HTTP schemes, potentially misleading users about the authenticity of a page.

Impact

Exploitation of this vulnerability could lead to moderate address bar spoofing, allowing malicious pages to appear as legitimate.

Remediation

Users can update to Firefox for iOS version 136 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.