CVE-2025-9183
BaseFortify
Publication date: 2025-08-19
Last updated on: 2026-04-13
Assigner: Mozilla Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mozilla | firefox | From 60.9.0 (exc) |
| mozilla | firefox | From 60.9.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-451 | The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a spoofing issue in the Address Bar component of Firefox browsers. It affects versions of Firefox earlier than 142 and Firefox ESR earlier than 140.2. Spoofing in this context means that an attacker could potentially manipulate the address bar to display misleading information to the user.
How can this vulnerability impact me? :
This vulnerability could allow an attacker to deceive users by displaying false or misleading URLs in the browser's address bar, potentially leading to phishing attacks or other forms of fraud where users are tricked into trusting malicious websites.