CVE-2025-8042

Publication date

2025-08-19 20:52:46

Family

mozilla

State

PUBLISHED

Description

Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability affects Firefox < 141.