参照: Official alpine advisory, NVD, CVE.org · CVE 詳細
Freshness: no update timestamp found; verify against the upstream OS advisory manually.
CVE-2025-6435: 2 source package rows (firefox, thunderbird); 220 state rows across 2 repos (3.22-community, edge-community); fixed 0, open 220.
If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file extension. This could have led to the user inadvertently running a malicious executable. This vulnerability was fixed in Firefox 140 and Thunderbird 140.