PT-2025-25208 · Mozilla · Vpn
Egor Filatov
·
Published
2025-05-30
·
Updated
2025-06-11
·
CVE-2025-5687
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mozilla VPN versions 2.28.0 and earlier (macOS)
Description
A vulnerability in Mozilla VPN for macOS allows privilege escalation from a normal user to root. This issue only affects Mozilla VPN on macOS, with other operating systems being unaffected.
Recommendations
For Mozilla VPN version 2.28.0 and earlier on macOS, update to a version that contains a fix for this issue to prevent privilege escalation.
Fix
LPE
Improper Privilege Management
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vpn