CVE-2025-8042: Mozilla Firefox
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability was fixed in Firefox 141.
Affected products
- Mozilla Firefox: before 141.0 (fixed in 141.0)
Published 2025-08-19. Last modified 2026-09-30.