Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*, +2 more
- < 141
A vulnerability in Firefox for Android versions prior to 141 allowed sandboxed iframes, lacking the 'allow-downloads' attribute, to initiate downloads. This issue represents a breach of the iframe's sandbox restrictions, potentially leading to unauthorized file downloads.
This vulnerability could be exploited to bypass iframe sandboxing, allowing for unauthorized downloads to be initiated on the user's device.
Users can update to Firefox for Android version 141 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.