CVE-2025-6435: Mozilla Firefox
High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.
If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file extension. This could have led to the user inadvertently running a malicious executable. This vulnerability was fixed in Firefox 140 and Thunderbird 140.
Affected products
Published 2025-06-24. Last modified 2026-09-30.