CVE-2025-11720
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-14

Last updated on: 2026-04-13

Assigner: Mozilla Corporation

Description
The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability was fixed in Firefox 144.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-14
Last Modified
2026-04-13
Generated
2026-05-07
AI Q&A
2025-10-14
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
google android *
mozilla firefox From 60.9.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-451 The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability in Firefox and Firefox Focus on Android involves the custom tab feature only displaying the 'site' part of the URL, not the full hostname. This means that user-supplied content hosted on a subdomain could trick users into believing it is from a different subdomain of the same site, potentially misleading them about the true origin of the content.


How can this vulnerability impact me? :

The vulnerability can be used to deceive users by making malicious or untrusted content appear as if it comes from a trusted subdomain. This could lead to phishing attacks or other forms of social engineering where users are misled about the authenticity of the content they are viewing.


What immediate steps should I take to mitigate this vulnerability?

Update Firefox and Firefox Focus on Android to version 144 or later, as versions prior to 144 are affected by this vulnerability.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart