Input validation error in Firefox for Android - CVE-2025-4086

 

Input validation error in Firefox for Android - CVE-2025-4086

Published: April 29, 2025


Vulnerability identifier: #VU108052
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-4086
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a spoofing attack.

The vulnerability exists due to insufficient validation of file names. A remote attacker can trick the victim into downloading a specially crafted file containing a large number of encoded newline characters in its name and obscure the file's extension when displayed in the download dialog.


Affected software

Firefox for Android
Mozilla Thunderbird

How to mitigate CVE-2025-4086

Install updates from vendor's website.

Firefox for Android - update to 138.0
Mozilla Thunderbird - update to 138.0

External References

Related Security Bulletins