{"id":"CVE-2025-11720","title":"The Firefox and Firefox Focus UI for the Android custom tab feature only showed the \"site\" that was loaded, not the full hostname","summary":"The Firefox and Firefox Focus UI for the Android custom tab feature only showed the \"site\" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","cwe":["CWE-451"],"vendor":"mozilla","product":"firefox","affected":["firefox < 144.0"],"patched":["firefox 144.0"],"published":"2025-10-14","updated":"2026-09-30","sourceUpdated":"2026-09-30T17:10:00.187","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-11720","references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1979534","label":"security@mozilla.org"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1984370","label":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2025-81/","label":"security@mozilla.org"}],"tags":["nvd"],"epss":0.00268,"epssPercentile":0.17067,"ingestedAt":"2026-09-30T17:13:20.715Z","slug":"CVE-2025-11720","body":"## Overview\n\nThe Firefox and Firefox Focus UI for the Android custom tab feature only showed the \"site\" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability was fixed in Firefox 144.\n\n## Affected\n\n- `firefox < 144.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `firefox 144.0`","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}