#VU116996 Protection mechanism failure in Mozilla products - CVE-2025-11712
Published: October 14, 2025
Mozilla Firefox
Firefox ESR
Firefox for Android
Mozilla
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient implementation of security measures. A malicious page can use the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This can lead to an XSS on a site that unsafely serves files without a content-type header.