CVE-2025-11718: Mozilla Firefox
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event. This vulnerability was fixed in Firefox 144.
Affected products
- Mozilla Firefox: before 144.0 (fixed in 144.0)
Published 2025-10-14. Last modified 2026-10-08.