CVE-2025-11716

Description

Links in a sandboxed iframe could open an external app on Android without the required allow- permission. This vulnerability was fixed in Firefox 144 and Thunderbird 144.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.028

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Mozilla Firefox (144.0)Windows
Multiple vulnerabilities are fixed in Mozilla Firefox (x64) (144.0)Windows
Multiple vulnerabilities are fixed in Mozilla Thunderbird (144.0)Windows
Multiple vulnerabilities are fixed in Mozilla Thunderbird (x64) (144.0)Windows
Vulnerabilities CVE-2025-11714,CVE-2025-11716,CVE-2025-11719,CVE-2025-11721 are affected in Mozilla Thunderbird 143.9Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 143.9Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 143.9Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird 143.9Windows
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (144.0)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (144.0.2)Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-352416Mozilla Firefox (144.0)
PATCH-352417Mozilla Firefox (x64) (144.0)
PATCH-352439Mozilla Thunderbird (144.0)
PATCH-352440Mozilla Thunderbird (x64) (144.0)
PATCH-352417Mozilla Firefox (x64) (144.0)
PATCH-352416Mozilla Firefox (144.0)
PATCH-613630Mozilla Firefox For Mac (147.0.4)
PATCH-613630Mozilla Firefox For Mac (147.0.4)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234