---
id: CVE-2025-55028
title: >-
  Malicious scripts utilizing repetitive JavaScript alerts could prevent client
  user interaction in some scenarios and allow for denial of service attacks
summary: >-
  Malicious scripts utilizing repetitive JavaScript alerts could prevent client
  user interaction in some scenarios and allow for denial of service attacks.
  This vulnerability was fixed in Firefox for iOS 142.
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
vendor: mozilla
product: firefox
affected:
  - firefox < 142.0
patched:
  - firefox 142.0
published: '2025-08-19'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T18:10:00.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-55028'
references:
  - url: 'https://bugzilla.mozilla.org/show_bug.cgi?id=1850240'
    label: security@mozilla.org
  - url: 'https://www.mozilla.org/security/advisories/mfsa2025-68/'
    label: security@mozilla.org
tags:
  - nvd
epss: 0.00222
epssPercentile: 0.11537
ingestedAt: '2026-09-30T18:17:24.453Z'
---

## Overview

Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service attacks. This vulnerability was fixed in Firefox for iOS 142.

## Affected

- `firefox < 142.0`

## Remediation

Upgrade past the affected range:

- `firefox 142.0`
