CVE-2025-23109EPSS p7.0%

CVE-2025-23109CVE-2025-23109

mozilla / firefox

Description

Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address. This vulnerability was fixed in Firefox for iOS 134.

Scoring

CVSS 6.5 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS0.18% probability of exploitation · percentile 7.0% · 2026-10-05T12:00:23Z
Last modified2026-10-05
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.