CVE-2025-11716
BaseFortify
Publication date: 2025-10-14
Last updated on: 2026-04-13
Assigner: Mozilla Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mozilla | thunderbird | to 140.0 (inc) |
| android | * | |
| mozilla | firefox | From 60.9.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability occurs when links inside a sandboxed iframe on Android devices can open an external application without having the necessary "allow-" permission. It affects Firefox and Thunderbird versions earlier than 144.
How can this vulnerability impact me? :
The vulnerability could allow a malicious link within a sandboxed iframe to launch external applications on an Android device without user consent or proper permission. This could lead to unauthorized app launches, potentially exposing the user to further attacks or privacy risks.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, update Firefox and Thunderbird to version 144 or later, as the issue affects versions prior to 144 and is fixed in 144.