A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
https://www.mozilla.org/security/advisories/mfsa2024-68/
https://www.mozilla.org/security/advisories/mfsa2024-67/
https://www.mozilla.org/security/advisories/mfsa2024-64/