We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox < 140 and Firefox ESR < 128.12.
Reserved 2025-06-20 | Published 2025-06-24 | Updated 2025-06-24 | Assigner mozillaIncorrect parsing of URLs could have allowed embedding of youtube.com
Masato Kinugawa
bugzilla.mozilla.org/show_bug.cgi?id=1970658
www.mozilla.org/security/advisories/mfsa2025-51/
www.mozilla.org/security/advisories/mfsa2025-53/
Support options