CVE-2025-11716: Mozilla Firefox

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thunderbird 144.

Affected products

  • Mozilla Firefox: before 144.0 (fixed in 144.0)
  • Mozilla Thunderbird: before 144.0 (fixed in 144.0)

Published 2025-10-14. Last modified 2026-06-17.