CVE-2025-5020: Mozilla Firefox

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website addresses if the URLs utilized non-HTTP schemes used internally by the Firefox iOS client. This vulnerability was fixed in Firefox for iOS 139.

Affected products

  • Mozilla Firefox: before 139.0 (fixed in 139.0)

Published 2025-05-21. Last modified 2026-10-05.