Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage This vulnerability affects Focus < 138.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.
Link | Tags |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1951533 | issue tracking |
https://www.mozilla.org/security/advisories/mfsa2025-33/ | vendor advisory |