Home Any version before 134
affected
Description
When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 134.
Problem types
Address bar spoofing using an invalid protocol scheme on Firefox for Android
Product status
Credits
Umar Farooq
References
bugzilla.mozilla.org/show_bug.cgi?id=1929584
www.mozilla.org/security/advisories/mfsa2025-01/