CVE-2025-11718

Description

When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event. This vulnerability was fixed in Firefox 144.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.026

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Mozilla Firefox (144.0)Windows
Multiple vulnerabilities are fixed in Mozilla Firefox (x64) (144.0)Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 143.9Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 143.9Windows
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (144.0)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (144.0.2)Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-352416Mozilla Firefox (144.0)
PATCH-352417Mozilla Firefox (x64) (144.0)
PATCH-352417Mozilla Firefox (x64) (144.0)
PATCH-352416Mozilla Firefox (144.0)
PATCH-613630Mozilla Firefox For Mac (147.0.4)
PATCH-613630Mozilla Firefox For Mac (147.0.4)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234