CVE-2025-11720
Publication date 14 October 2025
Last updated 15 October 2025
Ubuntu priority
Description
The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability affects Firefox < 144.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | 25.10 questing |
Not affected
|
25.04 plucky |
Not affected
|
|
24.04 LTS noble |
Not affected
|
|
22.04 LTS jammy |
Not affected
|
|
thunderbird | 25.10 questing |
Not affected
|
25.04 plucky |
Not affected
|
|
24.04 LTS noble |
Not affected
|
|
22.04 LTS jammy |
Not affected
|
|
mozjs38 | 25.10 questing | Not in release |
25.04 plucky | Not in release | |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
18.04 LTS bionic |
Needs evaluation
|
|
mozjs52 | 25.10 questing | Not in release |
25.04 plucky | Not in release | |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Ignored | |
18.04 LTS bionic | Ignored | |
mozjs68 | 25.10 questing | Not in release |
25.04 plucky | Not in release | |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Ignored | |
mozjs78 | 25.10 questing | Not in release |
25.04 plucky | Not in release | |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Ignored | |
mozjs91 | 25.10 questing | Not in release |
25.04 plucky | Not in release | |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Ignored | |
mozjs102 | 25.10 questing | Not in release |
25.04 plucky | Not in release | |
24.04 LTS noble | Ignored | |
22.04 LTS jammy | Ignored | |
mozjs115 | 25.10 questing | Not in release |
25.04 plucky | Ignored | |
24.04 LTS noble | Ignored | |
22.04 LTS jammy | Not in release |
Notes
mdeslaur
mozjs* contain a copy of the SpiderMonkey JavaScript engine. It is not feasible to backport security fixes to the mozjs* packages, as such, marking them as ignored. starting with Ubuntu 22.04, the firefox package is just a script that installs the Firefox snap starting with Ubuntu 24.04, the thunderbird package is just a script that installs the Thunderbird snap