PT-2025-13197 · Mozilla+1 · Firefox+1

Andrew Mccreight

·

Published

2025-03-27

·

Updated

2026-04-14

·

CVE-2025-2857

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 136.0.4 Mozilla Firefox ESR versions prior to 128.8.1 Mozilla Firefox ESR versions prior to 115.21.1
Description A critical vulnerability exists in Mozilla Firefox on Windows systems, allowing for a sandbox escape. This flaw is related to incorrect handling of inter-process communication (IPC) and could allow a compromised child process to gain unintended privileges, potentially leading to arbitrary code execution. The vulnerability was identified after a similar issue was found and patched in Google Chrome and has been actively exploited. The vulnerability affects the browser's sandbox, which is a security mechanism designed to isolate browser processes and prevent malicious code from accessing the underlying operating system. Exploitation of this vulnerability could allow an attacker to bypass these security measures and gain control of the affected system.
Recommendations Update Firefox to version 136.0.4 or later. Update Firefox ESR to version 128.8.1 or later. Update Firefox ESR to version 115.21.1 or later.

Fix

Race Condition

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

ALT-PU-2025-4968
ALT-PU-2025-5829
ALT-PU-2025-6353
ALT-PU-2025-7697
BDU:2025-03530
CVE-2025-2857
OPENSUSE-SU-2025:14948-1
OPENSUSE-SU-2025:14958-1
OPENSUSE-SU-2025:14961-1

Affected Products

Alt Linux
Firefox