CVE-2025-8364: Mozilla Firefox
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 141.
Affected products
- Mozilla Firefox: before 141.0 (fixed in 141.0)
Published 2025-08-19. Last modified 2026-10-05.