๐Ÿ” CVE Alert

CVE-2025-11720

HIGH 8.1

Spoofing risk in Android custom tabs

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability was fixed in Firefox 144.

Vendor mozilla
Product firefox
Ecosystems
Industries
Technology
Published Oct 14, 2025
Last Updated Apr 13, 2026
Stay Ahead of the Next One

Get instant alerts for mozilla firefox

Be the first to know when new high vulnerabilities affecting mozilla firefox are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Mozilla / Firefox
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
bugzilla.mozilla.org: https://bugzilla.mozilla.org/show_bug.cgi?id=1979534 bugzilla.mozilla.org: https://bugzilla.mozilla.org/show_bug.cgi?id=1984370 mozilla.org: https://www.mozilla.org/security/advisories/mfsa2025-81/

Credits

Michel Le Bihan