Impact
Sandboxed iframes on webpages can trigger a file download on the device even when the parent page declares sandbox restrictions. This flaw allows a user to receive a download intended to be blocked by the sandbox, representing an improper verification or authorization weakness (CWE-693). The impact is the unauthorized acquisition of data on the device without user consent.
Affected Systems
Mozilla Firefox for iOS is affected. Versions before 141 contain the flaw, while version 141 and later incorporate the fix that prevents the sandboxed iframe download bypass.
Risk and Exploitability
The CVSS score of 9.8 classifies this vulnerability as critical. The EPSS score of less than 1% indicates a low probability of observed exploitation at this time. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could embed a sandboxed iframe in a malicious or compromised website presented to a user on an iOS device, causing the browser to initiate a download that bypasses the intended sandbox limits.
OpenCVE Enrichment
EUVD