CVE-2025-11718: Mozilla Firefox

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event. This vulnerability was fixed in Firefox 144.

Affected products

  • Mozilla Firefox: before 144.0 (fixed in 144.0)

Published 2025-10-14. Last modified 2026-10-08.