---
id: CVE-2025-54143
title: >-
  Sandboxed iframes on webpages could potentially allow downloads to the device,
  bypassing the expected sandbox restrictions declared on the parent page
summary: >-
  Sandboxed iframes on webpages could potentially allow downloads to the device,
  bypassing the expected sandbox restrictions declared on the parent page. This
  vulnerability was fixed in Firefox for iOS 141.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-693
vendor: mozilla
product: firefox
affected:
  - firefox < 141.0
patched:
  - firefox 141.0
published: '2025-08-19'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T18:10:00.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-54143'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1912671'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-60/'
    label: security@mozilla.org
tags:
  - nvd
epss: 0.00481
epssPercentile: 0.39139
ingestedAt: '2026-09-30T18:17:24.452Z'
---

## Overview

Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This vulnerability was fixed in Firefox for iOS 141.

## Affected

- `firefox < 141.0`

## Remediation

Upgrade past the affected range:

- `firefox 141.0`
