User Interface (UI) Misrepresentation of Critical Information Affecting github.com/mozilla-mobile/firefox-ios package, versions <138.0.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.03% (8th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-SWIFT-MOZILLAMOBILEFIREFOXIOS-10248212
  • published27 May 2025
  • disclosed30 Apr 2025
  • creditJames Lee

Introduced: 30 Apr 2025

CVE-2025-3859  (opens in a new tab)
CWE-451  (opens in a new tab)

How to fix?

Upgrade mozilla-mobile/firefox-ios to version 138.0.0 or higher.

Overview

mozilla-mobile/firefox-ios is a The source code and project files for the Firefox Focus application on the iOS platform.

Affected versions of this package are vulnerable to User Interface (UI) Misrepresentation of Critical Information due to the truncating behavior in the location view. An attacker can mislead users into believing they are visiting a legitimate site by manipulating the display of the URL in the address bar.

Note: This issue specifically affects Firefox Focus on iOS, which does not share the same code with Firefox

PoC

https://long-extended-subdomain-name-containing-many-letters-and-dashes.badssl.com/ysigsgksgkskgslgsogslgslgslgslgslgsogsogsogslgsogsyosoys

CVSS Base Scores

version 4.0
version 3.1