CVE-2025-6428

Source
https://cve.org/CVERecord?id=CVE-2025-6428
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-6428.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-6428
Downstream
Related
Published
2025-06-24T13:15:23.770Z
Modified
2026-04-10T05:33:44.360520Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to phishing attacks. This bug only affects Firefox for Android. Other versions of Firefox are unaffected. This vulnerability affects Firefox < 140.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "140.0"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-6428.json"