CVE-2025-55030: Mozilla Firefox
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline rather than downloading, potentially allowing for XSS attacks. This vulnerability was fixed in Firefox for iOS 142.
Affected products
- Mozilla Firefox: before 142.0 (fixed in 142.0)
Published 2025-08-19. Last modified 2026-10-05.