Mozilla Firefox and Thunderbird URL Bar Spoofing Vulnerability via Non-BMP Unicode Characters

Vulnerability

A spoofing vulnerability has been identified in Mozilla Firefox and Thunderbird. A crafted URL containing specific Unicode characters could have obscured the true origin of the page, potentially leading to a spoofing attack. This issue affects Firefox versions prior to 137, Firefox ESR versions prior to 128.9, Thunderbird versions prior to 137, and Thunderbird ESR versions prior to 128.9.

Impact

Exploitation of this vulnerability could lead to a spoofing attack, where the true origin of a webpage is obscured, potentially misleading users.

Remediation

Users can upgrade to Firefox 137, Firefox ESR 128.9, Thunderbird 137, or Thunderbird ESR 128.9 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.