On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-firefoxalma-upgrade-firefox-x11 | Mar 13, 2025 | Mar 4, 2025 | |
| Mfsa2025 14 | mozilla-firefox-upgrade-136_0 | Mar 5, 2025 | Mar 4, 2025 | |
| Mfsa2025 15 | mozilla-firefox-esr-upgrade-115_21 | Mar 5, 2025 | Mar 4, 2025 | |
| Mfsa2025 16 | mozilla-firefox-esr-upgrade-128_8 | Mar 5, 2025 | Mar 4, 2025 | |
| Mozilla Thunderbird | mozilla-thunderbird-upgrade-128_8 | Mar 5, 2025 | Mar 4, 2025 | |
| Oracle_linux | — | oracle-linux-upgrade-firefoxoracle-linux-upgrade-firefox-x11 | Mar 10, 2025 | Mar 4, 2025 |
| Redhat_linux | redhat-upgrade-firefoxredhat-upgrade-firefox-debuginforedhat-upgrade-firefox-debugsourceredhat-upgrade-firefox-x11 | Mar 10, 2025 | Mar 4, 2025 | |
| Rocky_linux | rocky-upgrade-firefoxrocky-upgrade-firefox-debuginforocky-upgrade-firefox-debugsource | Jul 31, 2025 | Jul 29, 2025 | |
| Suse | — | suse-upgrade-libmozjs-128-0suse-upgrade-mozillafirefoxsuse-upgrade-mozillafirefox-branding-upstreamsuse-upgrade-mozillafirefox-develsuse-upgrade-mozillafirefox-translations-commonsuse-upgrade-mozillafirefox-translations-othersuse-upgrade-mozillathunderbirdsuse-upgrade-mozillathunderbird-translations-commonsuse-upgrade-mozillathunderbird-translations-othersuse-upgrade-mozjs128suse-upgrade-mozjs128-devel | Mar 6, 2025 | Mar 4, 2025 |
| Ubuntu | ubuntu-upgrade-thunderbird | Jun 26, 2025 | Mar 4, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub