CVE-2025-8043: Mozilla Firefox

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Firefox 141.

Affected products

  • Mozilla Firefox: before 141.0 (fixed in 141.0)
  • Mozilla Thunderbird: before 141.0 (fixed in 141.0)

Published 2025-07-22. Last modified 2026-09-30.