Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wjv8-8vf9-mrv8

Опубликовано: 14 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability affects Firefox < 144.

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability affects Firefox < 144.

EPSS

Процентиль: 17%
0.00054
Низкий

8.1 High

CVSS3

Дефекты

CWE-451

Связанные уязвимости

CVSS3: 8.1
ubuntu
4 месяца назад

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability affects Firefox < 144.

CVSS3: 8.1
nvd
4 месяца назад

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability affects Firefox < 144.

CVSS3: 8.1
debian
4 месяца назад

The Firefox and Firefox Focus UI for the Android custom tab feature on ...

CVSS3: 8.1
fstec
4 месяца назад

Уязвимость пользовательского интерфейса браузеров Mozilla Firefox и Firefox Focus, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

EPSS

Процентиль: 17%
0.00054
Низкий

8.1 High

CVSS3

Дефекты

CWE-451