If web downloads fail with CORS errors while mobile works, apply a CORS config to the bucket: create a cors.json listing your origins and methods, then run gsutil cors set cors.json against the bucket. Include the upload-specific response headers when the app also uploads from the browser. Verify with gsutil cors get afterward.

Context: Official docs (FlutterFire firebase_storage web README): when using getData on the web platform, the bucket must have the correct CORS configuration, or the browser blocks the downloaded data with a CORS policy error even though the same download works fine on mobile. CORS for Firebase Storage is configured on the underlying Google Cloud Storage bucket with a cors.json applied via gsutil or gcloud, not in application code or the Firebase console.