Protection Mechanism Failure in Firefox for iOS - CVE-2025-54143

 

Protection Mechanism Failure in Firefox for iOS - CVE-2025-54143

Published: July 22, 2025


Vulnerability identifier: #VU113155
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-54143
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures. Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page


Affected software

Firefox for iOS

How to mitigate CVE-2025-54143

Install updates from vendor's website.

Firefox for iOS - update to 141.0

External References

Related Security Bulletins