External risk intelligence

Firefox for iOS Sandbox Escape Allows Unauthorized Downloads

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-54143

This vulnerability affects a client-side web browser application (Firefox for iOS). While web browsers interact with the internet, this specific issue involves sandboxed iframe behavior on the client device itself. It is not an internet-facing service, gateway, or server-side component, making it local-only or client-side execution.

Mozilla Firefox

before 141.0

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability involves sandboxed elements on webpages potentially allowing unexpected downloads, even when security measures are in place. The primary concern is confirming whether our users might be exposed to this client-side browser issue.

  • Webpages may allow unauthorized downloads.
  • Protects user data from web content.
  • Confirm relevance to our users.

Attack Path

How an attacker could exploit the issue

An attacker could trick a user into visiting a malicious webpage. This page would contain a sandboxed iframe that exploits a flaw in how Firefox for iOS handles downloads, allowing it to bypass security restrictions and download files directly to the user's device.

  • Requires visiting a malicious site.
  • Triggered by iframe download behavior.
  • Allows unauthorized file downloads.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, sandboxed iframes on webpages could allow downloads to the device, bypassing expected sandbox restrictions.

  • Device downloads.
  • Bypass sandbox restrictions.
  • Unauthorized file access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts users of Firefox for iOS, allowing sandboxed iframes to potentially bypass security restrictions and permit downloads. The first practical step is to identify affected users and devices, assess the business criticality of their browsing activities, and confirm the user or device owner before planning remediation.

  • Owner: Device and end-user support teams.
  • Verify: Affected users and their browsing habits.
  • Action: Coordinate user updates and communication.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Firefox for iOS and what is it used for?

Firefox for iOS is a mobile web browser developed by Mozilla specifically for Apple's mobile operating system. It allows users to navigate the web, manage bookmarks, and sync browsing history across devices. Like other browsers, it uses sandboxing technology to isolate web content and protect your device's core system from potentially harmful or malicious scripts encountered while surfing the internet.

What does CVE-2025-54143 mean for my security?

This vulnerability is classified as CWE-693: Protection Mechanism Failure. It means the browser fails to correctly enforce security boundaries for sandboxed iframes. Normally, these frames are isolated to prevent them from performing certain actions. In this case, the weakness allows a webpage to bypass those restrictions and trigger file downloads to your device without the intended sandbox protections stopping it.

How is this download vulnerability triggered?

An attacker must entice a user to visit a specially crafted or malicious webpage. The flaw is triggered when the browser processes a sandboxed iframe on that page configured to initiate a file download. Note that simply having the browser installed is not enough; the bug does not trigger through passive background processes or normal navigation to trusted, secure websites.

Is my device at high risk according to Halo Surface Signal?

Halo Surface Signal labels this as very unlikely to pose a broad infrastructure threat. Because Firefox for iOS is a client-side application rather than an internet-facing server or gateway, the risk is confined to individual user devices. While important for personal security, it does not represent an exposed network service that attackers can remotely scan or compromise across an entire organization’s perimeter.

Do I need to update my software to fix this?

Yes. Since this is a client-side browser issue, the primary solution is to ensure you are running a version of Firefox for iOS that includes the fix. Organizations should identify users or devices still running versions prior to 141.0. Once identified, coordinate with those users to update their application through the official app store to ensure the browser’s sandbox protections are restored.

References