CVE-2025-8042: Mozilla Firefox

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability was fixed in Firefox 141.

Affected products

  • Mozilla Firefox: before 141.0 (fixed in 141.0)

Published 2025-08-19. Last modified 2026-09-30.