Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-3122 | Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134. |
Mon, 13 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134. | Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability was fixed in Firefox for iOS 134. |
| Title | Firefox Mobile iOS Full Address Bar Spoof Using Open in New Tab and Javascript URI |
Thu, 03 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla
Mozilla firefox |
|
| CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:* | |
| Vendors & Products |
Mozilla
Mozilla firefox |
Mon, 13 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Sat, 11 Jan 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134. | |
| References |
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2026-04-13T14:29:24.969Z
Reserved: 2025-01-10T21:00:17.659Z
Link: CVE-2025-23108
Updated: 2025-01-13T17:46:08.182Z
Status : Modified
Published: 2025-01-11T04:15:06.280
Modified: 2026-04-13T15:16:54.423
Link: CVE-2025-23108
No data.
OpenCVE Enrichment
Updated: 2026-04-21T00:00:13Z
EUVD