ZeroHour

CVE-2025-55030

CVSS 3.1
6.1 medium
EPSS
<1%p5
Published
()
Modified
Description

Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline rather than downloading, potentially allowing for XSS attacks. This vulnerability was fixed in Firefox for iOS 142.

Vendors
mozilla
Products
firefox
Weakness
CWE-640
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.