A crafted URL using a blob: URI could have hidden the...
Moderate severity
Unreviewed
Published
Aug 19, 2025
to the GitHub Advisory Database
•
Updated Aug 20, 2025
Description
Published by the National Vulnerability Database
Aug 19, 2025
Published to the GitHub Advisory Database
Aug 19, 2025
Last updated
Aug 20, 2025
A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack.
Note: This issue only affected Android operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 141.
References