Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sandbox escape. The original vulnerability was being exploited in the wild. *This only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 136.0.4, Firefox ESR 128.8.1, and Firefox ESR 115.21.1.
CVSS Details
- CVSS 3.1 Base Score: 10
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Mfsa2025 19 | — | Upgrade to Mozilla Firefox ESR version 115.21.1Upgrade to Mozilla Firefox version 136.0.4Upgrade to Mozilla Firefox ESR version 128.8.1 | Mar 28, 2025 | Mar 27, 2025 |
| Suse | — | Upgrade mozillafirefox-translations-commonUpgrade mozillafirefox-translations-otherUpgrade mozjs128Upgrade mozillafirefox-develUpgrade mozillafirefoxUpgrade libmozjs-128-0Upgrade mozjs128-devel | Jul 16, 2025 | Mar 27, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub