CVE-2025-4086: Mozilla Firefox
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.*. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
Affected products
Published 2025-04-29. Last modified 2026-09-30.