CVE-2025-10290
Last modified
CVE-2025-10290 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Opening links via the contextual menu in Focus iOS for certain URL schemes would fail to load but would not refresh the toolbar correctly, allowing attackers to spoof websites if users were coerced into opening a link explicitly through a long-press. This vulnerability was fixed in Focus for iOS 143.0.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Opening links via the contextual menu in Focus iOS for certain URL schemes would fail to load but would not refresh the toolbar correctly, allowing attackers to spoof websites if users were coerced into opening a link explicitly through a long-press. This vulnerability was fixed in Focus for iOS 143.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox Focus | < 143.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1975566Issue Tracking, Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2025-76/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-10290?
How severe is CVE-2025-10290?
How do I fix CVE-2025-10290?
Are you affected by CVE-2025-10290?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
