CVE-2025-54143: Sandboxed iframes could allow local downloads despite sandbox restrictions
Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-54143?
CVE-2025-54143 is considered a medium severity vulnerability due to its potential to bypass sandbox restrictions.
How do I fix CVE-2025-54143?
To mitigate CVE-2025-54143, users should update their Mozilla Firefox and Apple iOS to the latest versions as patches may be included.
What systems are affected by CVE-2025-54143?
CVE-2025-54143 affects Mozilla Firefox version 141 and certain versions of Apple iOS.
What risks does CVE-2025-54143 pose to users?
CVE-2025-54143 could allow malicious downloads to the user’s device, posing a risk to data security and system integrity.
Is there any workaround for CVE-2025-54143 before applying a fix?
Currently, the best workaround for CVE-2025-54143 is to refrain from using sandboxed iframes until a fix is applied.