CVE-2025-4086: Specially crafted filename could be used to obscure download type
A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.. This vulnerability was fixed in Firefox 138 and Thunderbird 138.
Other sources
A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog.This bug only affects Firefox for Android. Other versions of Firefox are unaffected.
— Mozilla
A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog.This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-4086?
CVE-2025-4086 is classified as a moderate severity vulnerability affecting Firefox for Android.
How does CVE-2025-4086 affect users?
CVE-2025-4086 affects users by potentially obscuring a file's extension in the download dialog, which can lead to confusion over file types.
What versions of Firefox are affected by CVE-2025-4086?
CVE-2025-4086 affects versions of Firefox for Android prior to 138.
What versions of Thunderbird are affected by CVE-2025-4086?
CVE-2025-4086 affects versions of Thunderbird prior to 138.
How do I fix CVE-2025-4086?
To fix CVE-2025-4086, update Firefox for Android and Thunderbird to version 138 or later.