CVE-2025-23108: Mozilla Firefox

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability was fixed in Firefox for iOS 134.

Affected products

  • Mozilla Firefox: before 134.0 (fixed in 134.0)

Published 2025-01-11. Last modified 2026-10-05.