CVE-2025-0246: Address bar spoofing using an invalid protocol scheme on Firefox for Android
When using an invalid protocol scheme, an attacker could spoof the address bar. Note: This issue only affected Android operating systems. Other operating systems are unaffected. Note: This issue is a different issue from CVE-2025-0244. This vulnerability was fixed in Firefox 134.
Other sources
When using an invalid protocol scheme, an attacker could spoof the address bar. Note: This issue only affected Android operating systems. Other operating systems are unaffected.Note: This issue is a different issue from CVE-2025-0244.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-0246?
CVE-2025-0246 is considered a moderate severity vulnerability affecting Firefox versions below 134.
How do I fix CVE-2025-0246?
To fix CVE-2025-0246, upgrade to Mozilla Firefox version 134 or later.
Who is affected by CVE-2025-0246?
CVE-2025-0246 affects users of Mozilla Firefox on Android operating systems.
What type of attack does CVE-2025-0246 enable?
CVE-2025-0246 could enable an attacker to spoof the address bar through the use of an invalid protocol scheme.
Is there a workaround for CVE-2025-0246?
No specific workaround is recommended for CVE-2025-0246; the best solution is to update to the latest version of Firefox.