CVE-2025-54143Critical· 9.8▾ MidnightSandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This vulnerability was fixed in Firefox for iOS 141.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This vulnerability was fixed in Firefox for iOS 141.
firefox < 141.0Upgrade past the affected range:
firefox 141.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92079Critical· 9.1Mitigation bypass in the Widget: Win32 component
CVE-2026-92075Critical· 9.1Mitigation bypass in the Networking component
CVE-2026-92074High· 8.8Mitigation bypass in the Popup Blocker component
CVE-2026-92018Critical· 9.6Sandbox escape in the DOM: Core & HTML component
CVE-2026-92019High· 8.1Mitigation bypass in the Remote Settings Client component
CVE-2026-92066Critical· 9.8Sandbox escape in the Profile Backup component