CVE-2025-11720
8.1Mozilla · Firefox and Firefox Focus
A UI spoofing vulnerability in the Android custom tab feature allows attackers to disguise subdomains, potentially misleading users regarding the authenticity of the loaded site.
Executive summary
Mozilla Firefox and Firefox Focus for Android contain a user interface flaw that permits subdomain spoofing, posing a significant risk of user deception and credential theft.
Vulnerability
This vulnerability involves an improper UI representation in the Android custom tab feature, where the browser fails to display the full hostname. An unauthenticated attacker can exploit this to trick users into believing they are interacting with a different subdomain of the same site.
Business impact
The ability to spoof hostnames in the browser UI facilitates sophisticated phishing attacks, which can lead to the unauthorized collection of sensitive user credentials or the delivery of malicious payloads. With a CVSS score of 8.1, this high-severity flaw represents a substantial risk to organizational security, particularly for mobile users who rely on the browser to verify site legitimacy.
Remediation
Immediate Action: Update all instances of Mozilla Firefox and Firefox Focus on Android to version 144 or later.
Proactive Monitoring: Security teams should monitor for unusual spikes in credential reset requests or reports of suspicious site activity originating from mobile devices.
Compensating Controls: Implement robust multi-factor authentication across all corporate services to mitigate the impact of potentially compromised credentials obtained via phishing.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
Given the severity of this UI spoofing flaw, organizations must prioritize the deployment of the version 144 update across all mobile endpoints. Ensuring that users are running the latest version of the browser is the only effective way to neutralize the risk of domain misidentification and subsequent phishing attacks.
More Mozilla CVEs
Sources
Originally found and disclosed by Michel Le Bihan, per the CVE Program record.