Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This vulnerability was fixed in Firefox for iOS 141.
References
| Link | Resource |
|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=1912671 | Issue Tracking Permissions Required |
| https://www.mozilla.org/security/advisories/mfsa2025-60/ | Vendor Advisory |
Configurations
History
13 Apr 2026, 15:17
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This vulnerability was fixed in Firefox for iOS 141. |
21 Aug 2025, 18:39
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://bugzilla.mozilla.org/show_bug.cgi?id=1912671 - Issue Tracking, Permissions Required | |
| References | () https://www.mozilla.org/security/advisories/mfsa2025-60/ - Vendor Advisory | |
| CPE | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:* | |
| First Time |
Mozilla firefox
Mozilla |
20 Aug 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-693 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
20 Aug 2025, 14:40
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
19 Aug 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-08-19 21:15
Updated : 2026-04-13 15:17
NVD link : CVE-2025-54143
Mitre link : CVE-2025-54143
CVE.ORG link : CVE-2025-54143
JSON object : View
Products Affected
mozilla
- firefox
CWE
CWE-693
Protection Mechanism Failure
