CVE-2025-8043User Interface (UI) Misrepresentation of Critical Information in Mozilla Firefox

Severity
9.8CRITICALNVD
EPSS
0.1%
top 64.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 22

Description

Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Firefox 141.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDmozilla/firefox< 141.0
NVDmozilla/thunderbird< 141.0

🔴Vulnerability Details

3
OSV
CVE-2025-8043: Focus incorrectly truncated URLs towards the beginning instead of around the origin2025-07-22
CVEList
Incorrect URL truncation2025-07-22
GHSA
GHSA-ww6j-fhx6-wrxh: Focus incorrectly truncated URLs towards the beginning instead of around the origin2025-07-22

📋Vendor Advisories

3
Red Hat
firefox: thunderbird: Incorrect URL truncation2025-07-22
Debian
CVE-2025-8043: firefox - Focus incorrectly truncated URLs towards the beginning instead of around the ori...2025
Mozilla
Mozilla Foundation Security Advisory 2025-56: CVE-2025-8043
CVE-2025-8043 — Mozilla Firefox vulnerability | cvebase