CVE-2025-8042: Sandboxed iframe could start downloads
Firefox for Android allowed a sandboxed iframe without the allow-downloads attribute to start downloads. This vulnerability was fixed in Firefox 141.
Other sources
Firefox for Android allowed a sandboxed iframe without the allow-downloads attribute to start downloads.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 141 - Upgrade
Upgrade
Firefox for Androidto a version that resolves this vulnerability.Fixed in 141
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-8042?
CVE-2025-8042 is considered a moderate severity vulnerability.
How do I fix CVE-2025-8042?
To fix CVE-2025-8042, users should update Firefox for Android to version 142 or later.
What does CVE-2025-8042 affect?
CVE-2025-8042 affects Firefox for Android versions prior to 142.
What is the impact of exploiting CVE-2025-8042?
Exploiting CVE-2025-8042 may allow a sandboxed iframe to start downloads without proper permissions.
When was CVE-2025-8042 disclosed?
CVE-2025-8042 was disclosed in 2025.