CVE-2025-4086

Publication date

2025-04-29 13:13:40

Family

mozilla

State

PUBLISHED

Description

A specially crafted filename containing a large number of encoded newline characters could obscure the files extension when displayed in the download dialog. *This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.* This vulnerability affects Firefox < 138 and Thunderbird < 138.