CVE-2025-11716: Sandboxed iframes allowed links to open in external apps (Android only)
Published Oct 14, 2025
·Updated
Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission.
Affected Software
5 affected componentsFixes available
Mozilla Firefox<144
144
Mozilla Thunderbird<144
144
All of the following
Any of the following
Mozilla Firefox<144.0
Mozilla Thunderbird<144.0
Google Android
Event History
Oct 14, 2025
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
Updated
via Mozilla·12:00 AM
Affected Software
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-11716?
CVE-2025-11716 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2025-11716?
To fix CVE-2025-11716, update Firefox or Thunderbird to version 144 or later.
3
What systems are affected by CVE-2025-11716?
CVE-2025-11716 affects Firefox versions prior to 144 and Thunderbird versions prior to 144.
4
How does CVE-2025-11716 impact users?
CVE-2025-11716 allows links within sandboxed iframes to open external applications without the required permissions, posing security risks.
5
Was there a fix released for CVE-2025-11716?
Yes, a fix for CVE-2025-11716 was included in the release of Firefox and Thunderbird version 144.