PT-2025-41904 · Mozilla+1 · Thunderbird+2

Axel Chong

·

Published

2025-10-14

·

Updated

2025-11-10

·

CVE-2025-11716

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 144 Thunderbird versions prior to 144
Description A flaw exists where links within a sandboxed iframe can trigger the opening of an external application on Android devices, bypassing the necessary "allow-" permissions. This could potentially allow for unauthorized access or execution of applications.
Recommendations Update Firefox to version 144 or later. Update Thunderbird to version 144 or later.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

ALT-PU-2025-13476
ALT-PU-2025-13478
CVE-2025-11716
OPENSUSE-SU-2025:15645-1

Affected Products

Alt Linux
Firefox
Thunderbird