CVE-2025-23108

Severity
4.3MEDIUM
EPSS
0.8%
top 26.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 11
Latest updateJan 13

Description

Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDmozilla/firefox< 134.0
CVEListV5mozilla/firefox_for_iosunspecified134

🔴Vulnerability Details

3
OSV
CVE-2025-23108: Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab2025-01-13
GHSA
GHSA-v3v8-99w9-8c5h: Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab2025-01-11
CVEList
CVE-2025-23108: Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab2025-01-11

📋Vendor Advisories

2
Debian
CVE-2025-23108: firefox - Opening Javascript links in a new tab via long-press in the Firefox iOS client c...2025
Mozilla
Mozilla Foundation Security Advisory 2025-06: CVE-2025-23108
CVE-2025-23108 (MEDIUM CVSS 4.3) | Opening Javascript links in a new t | cvebase.io