CVE-2025-6428Open Redirect in Mozilla Firefox

CWE-601Open Redirect7 documents7 sources
Severity
4.3MEDIUMNVD
EPSS
0.1%
top 80.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 24
Latest updateJun 26

Description

When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to phishing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.*. This vulnerability was fixed in Firefox 140.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages1 packages

NVDmozilla/firefox< 140.0

🔴Vulnerability Details

3
GHSA
GHSA-34r6-q8c8-23mx: When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to2025-06-26
OSV
CVE-2025-6428: When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to2025-06-24
CVEList
Firefox for Android opened URLs specified in a link querystring parameter2025-06-24

📋Vendor Advisories

3
Red Hat
firefox: Firefox for Android opened URLs specified in a link querystring parameter2025-06-24
Debian
CVE-2025-6428: firefox - When a URL was provided in a link querystring parameter, Firefox for Android wou...2025
Mozilla
Mozilla Foundation Security Advisory 2025-51: CVE-2025-6428
CVE-2025-6428 — Open Redirect in Mozilla Firefox | cvebase