CVE-2025-0244: Address bar spoofing using an invalid protocol scheme on Firefox for Android
When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. Note: This issue only affected Android operating systems. Other operating systems are unaffected.. This vulnerability was fixed in Firefox 134.
Other sources
When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. Note: This issue only affected Android operating systems. Other operating systems are unaffected.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-0244?
CVE-2025-0244 is considered a moderate severity vulnerability affecting Firefox versions prior to 134.
How do I fix CVE-2025-0244?
To fix CVE-2025-0244, update your Firefox browser to version 134 or later.
Who is affected by CVE-2025-0244?
Only users of Mozilla Firefox on Android operating systems are affected by CVE-2025-0244.
Can CVE-2025-0244 be exploited remotely?
Yes, CVE-2025-0244 can be exploited remotely by an attacker through malformed URL redirects.
What happens if I don't mitigate CVE-2025-0244?
If not mitigated, CVE-2025-0244 could allow an attacker to spoof the address bar, potentially misleading users.