First published: Tue Apr 29 2025(Updated: )
A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 138 and Thunderbird < 138.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <138 | |
Thunderbird | <138 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4086 is classified as a moderate severity vulnerability affecting Firefox for Android.
CVE-2025-4086 affects users by potentially obscuring a file's extension in the download dialog, which can lead to confusion over file types.
CVE-2025-4086 affects versions of Firefox for Android prior to 138.
CVE-2025-4086 affects versions of Thunderbird prior to 138.
To fix CVE-2025-4086, update Firefox for Android and Thunderbird to version 138 or later.