CVE-2025-9183 โ€” User Interface (UI) Misrepresentation of Critical Information in Mozilla Firefox

Severity
6.5MEDIUMNVD
EPSS
0.0%
top 91.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 19

Description

Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox ESR 140.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

โ–ถNVDmozilla/firefox< 140.2.0+1

๐Ÿ”ดVulnerability Details

3
CVEList
Spoofing issue in the Address Bar componentโ†—2025-08-19
โ–ถ
OSV
CVE-2025-9183: Spoofing issue in the Address Bar componentโ†—2025-08-19
โ–ถ
GHSA
GHSA-vhcx-3xrg-8hjg: Spoofing issue in the Address Bar componentโ†—2025-08-19
โ–ถ

๐Ÿ“‹Vendor Advisories

4
Red Hat
firefox: Spoofing issue in the Address Bar componentโ†—2025-08-19
โ–ถ
Debian
CVE-2025-9183: firefox - Spoofing issue in the Address Bar component. This vulnerability affects Firefox ...โ†—2025
โ–ถ
Mozilla
Mozilla Foundation Security Advisory 2025-64: CVE-2025-9183โ†—
โ–ถ
Mozilla
Mozilla Foundation Security Advisory 2025-67: CVE-2025-9183โ†—
โ–ถ
CVE-2025-9183 โ€” Mozilla Firefox vulnerability | cvebase