When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 134.
https://www.securityweek.com/chrome-131-firefox-134-updates-patch-high-severity-vulnerabilities/