Mozilla Foundation Security Advisory 2025-33
Security vulnerability fixed in Focus for iOS 138
- Announced
- April 21, 2025
- Impact
- moderate
- Products
- Focus
- Fixed in
-
- Focus 138
#CVE-2025-3859: Firefox Focus elide URL allows address bar spoofing
- Reporter
- James Lee
- Impact
- moderate
Description
Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage