Potential Execution Risk in Firefox from Incomplete File Saving
CVE-2025-6435
8.1HIGH
What is CVE-2025-6435?
A vulnerability in Firefox allows users to save responses from the Network tab in Devtools without the proper .download
file extension. This mismanagement may inadvertently enable the execution of malicious executables, posing a security threat to users. The issue affects Firefox versions prior to 140, highlighting the importance of secure file handling practices in web browsers.
Affected Version(s)
Firefox < 140