CVE-2025-23109: Mozilla Firefox
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address. This vulnerability was fixed in Firefox for iOS 134.
Affected products
- Mozilla Firefox: before 134.0 (fixed in 134.0)
Published 2025-01-11. Last modified 2026-10-05.