PT-2025-44159 · Mozilla+1 · Firefox+1

Oskar L

·

Published

2025-10-28

·

Updated

2026-04-15

·

CVE-2025-12380

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 144.0.2
Description A compromised child process could trigger a use-after-free in the GPU or browser process through WebGPU-related IPC calls. This could potentially allow for escaping the child process sandbox.
Recommendations Update to Firefox version 144.0.2 or later.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2025-14358
BDU:2025-14537
CVE-2025-12380
OPENSUSE-SU-2025:15686-1

Affected Products

Alt Linux
Firefox