Mozilla Foundation Security Advisory 2025-33

Security vulnerability fixed in Focus for iOS 138

Announced
April 21, 2025
Impact
moderate
Products
Focus
Fixed in
  • Focus 138

#CVE-2025-3859: Firefox Focus elide URL allows address bar spoofing

Reporter
James Lee
Impact
moderate
Description

Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage

References