CVE-2025-54144
published 2025-08-19CVE-2025-54144: The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if a…
PriorityP426medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
EPSS
0.23%
13.4th percentile
The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if a user was tricked into clicking a link. This vulnerability was fixed in Firefox for iOS 141.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < 141.0 | 141.0 |
| mozilla | firefox | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
osv5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Mozilla
Mozilla Foundation Security Advisory 2025-60: CVE-2025-54144
vendor_mozilla·CVSS 5.4
CVE-2025-54144 [MEDIUM] Mozilla Foundation Security Advisory 2025-60: CVE-2025-54144
Mozilla Foundation Security Advisory 2025-60
CVE: CVE-2025-54144
Product: Firefox for iOS
Impact: moderate
Fixed in: Firefox for iOS 141
GHSA
GHSA-36p9-4jqp-qvg9: The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pa
ghsa_unreviewed·2025-08-19
CVE-2025-54144 [MEDIUM] CWE-601 GHSA-36p9-4jqp-qvg9: The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pa
The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if a user was tricked into clicking a link This vulnerability affects Firefox for iOS < 141.
OSV
CVE-2025-54144: The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pa
osv·2025-07-23·CVSS 5.4
CVE-2025-54144 [MEDIUM] CVE-2025-54144: The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pa
The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if a user was tricked into clicking a link. This vulnerability affects Firefox for iOS < 141.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-19
Published