CVE-2025-8042: Sandboxed iframe could start downloads
Published Jul 22, 2025
·Updated
Firefox for Android allowed a sandboxed iframe without the allow-downloads attribute to start downloads. This vulnerability was fixed in Firefox 141.
Other sources
Firefox for Android allowed a sandboxed iframe without the allow-downloads attribute to start downloads.
— Mozilla
Affected Software
3 affected componentsFixes available
Mozilla Firefox<141
141
All of the following
Mozilla Firefox<141.0
Google Android
Event History
Jul 22, 2025
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
Aug 19, 2025
CVE Published
via MITRE·08:52 PM
Data Sourced
via MITRE·08:52 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-8042?
CVE-2025-8042 is considered a moderate severity vulnerability.
2
How do I fix CVE-2025-8042?
To fix CVE-2025-8042, users should update Firefox for Android to version 142 or later.
3
What does CVE-2025-8042 affect?
CVE-2025-8042 affects Firefox for Android versions prior to 142.
4
What is the impact of exploiting CVE-2025-8042?
Exploiting CVE-2025-8042 may allow a sandboxed iframe to start downloads without proper permissions.
5
When was CVE-2025-8042 disclosed?
CVE-2025-8042 was disclosed in 2025.