4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Description
A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack.
*Note: This issue only affected Android operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 141.
*Note: This issue only affected Android operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 141.
Basic Information
ID
CVE-2025-8364
Source
mozilla
Published
Aug 19, 2025 at 20:52
Modified
Aug 20, 2025 at 15:17
Affected Product
Vendor
Mozilla
Product
Firefox
Version
unspecified
Affected Versions
Mozilla Firefox unspecified