Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability affects Firefox < 141.
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores