Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This vulnerability was fixed in Firefox for iOS 141.
Metrics
Affected Vendors & Products
References
History
Mon, 13 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page This vulnerability affects Firefox for iOS < 141. | Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This vulnerability was fixed in Firefox for iOS 141. |
| Title | Sandboxed iframes could allow local downloads despite sandbox restrictions |
Thu, 21 Aug 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla firefox
|
|
| CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:* | |
| Vendors & Products |
Mozilla firefox
|
Thu, 21 Aug 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple ios Mozilla Mozilla firefox For Ios |
|
| Vendors & Products |
Apple
Apple ios Mozilla Mozilla firefox For Ios |
Wed, 20 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-693 | |
| Metrics |
cvssV3_1
|
Tue, 19 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page This vulnerability affects Firefox for iOS < 141. | |
| References |
|
Status: PUBLISHED
Assigner: mozilla
Published: 2025-08-19T20:52:47.450Z
Updated: 2026-04-13T14:30:52.883Z
Reserved: 2025-07-17T02:35:52.284Z
Link: CVE-2025-54143
Updated: 2025-08-20T14:03:00.609Z
Status : Modified
Published: 2025-08-19T21:15:27.557
Modified: 2026-04-13T15:17:01.840
Link: CVE-2025-54143
No data.