Input validation error in Firefox for Android - CVE-2025-4086
Published: April 29, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a spoofing attack.
The vulnerability exists due to insufficient validation of file names. A remote attacker can trick the victim into downloading a specially crafted file containing a large number of encoded newline characters in its name and obscure the file's extension when displayed in the download dialog.
Affected software
Mozilla Thunderbird
How to mitigate CVE-2025-4086
Mozilla Thunderbird - update to 138.0