Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sandbox escape. The original vulnerability was being exploited in the wild. *This only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 136.0.4, Firefox ESR < 128.8.1, and Firefox ESR < 115.21.1.
2025-03-27T14:15:55.720
2025-10-31T14:16:12.670
Modified
CVSSv3.1: 10.0 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mozilla | firefox | < 136.0.4 | Yes |
| Application | mozilla | firefox | < 115.21.1 | Yes |
| Application | mozilla | firefox | < 128.8.1 | Yes |