4.3
CVE-2025-8364
- EPSS 0.22%
- Veröffentlicht 19.08.2025 20:52:46
- Zuletzt bearbeitet 05.10.2026 15:10:00
- Erkennungen
Address bar spoofing using an blob URI on Firefox for Android
A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 141.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.13 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
|
CWE-451 User Interface (UI) Misrepresentation of Critical Information
The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.
https://www.mozilla.org/security/advisories/mfsa2025-56/
https://bugzilla.mozilla.org/show_bug.cgi?id=1909609
https://bugzilla.mozilla.org/show_bug.cgi?id=1969937