CVE-2025-11716
Links in a sandboxed iframe could open an external app on Android without the required “allow-” permission. This vulnerability affects Firefox < 144 and Thunderbird < 144. More information : https://bugzilla.mozilla.org/show_bug.cgi?id=1818679
