CVE-2025-54143
published 2025-08-19CVE-2025-54143: Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This…
PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.45%
36.3th percentile
Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This vulnerability was fixed in Firefox for iOS 141.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < 141.0 | 141.0 |
| mozilla | firefox | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x7hr-j7rg-h68w: Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page
ghsa_unreviewed·2025-08-19
CVE-2025-54143 [CRITICAL] CWE-693 GHSA-x7hr-j7rg-h68w: Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page
Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page This vulnerability affects Firefox for iOS < 141.
OSV
CVE-2025-54143: Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page
osv·2025-07-23·CVSS 9.8
CVE-2025-54143 [CRITICAL] CVE-2025-54143: Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page
Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This vulnerability affects Firefox for iOS < 141.
Mozilla
Mozilla Foundation Security Advisory 2025-60: CVE-2025-54143
vendor_mozilla·CVSS 9.8
CVE-2025-54143 [CRITICAL] Mozilla Foundation Security Advisory 2025-60: CVE-2025-54143
Mozilla Foundation Security Advisory 2025-60
CVE: CVE-2025-54143
Product: Firefox for iOS
Impact: moderate
Fixed in: Firefox for iOS 141
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-19
Published