CVE-2025-2857

Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sandbox escape. The original vulnerability was being exploited in the wild. *This only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 136.0.4, Firefox ESR < 128.8.1, and Firefox ESR < 115.21.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*

History

31 Oct 2025, 14:16

Type Values Removed Values Added
CWE CWE-668

Information

Published : 2025-03-27 14:15

Updated : 2025-10-31 14:16


NVD link : CVE-2025-2857

Mitre link : CVE-2025-2857

CVE.ORG link : CVE-2025-2857


JSON object : View

Products Affected

mozilla

  • firefox
CWE
NVD-CWE-noinfo CWE-668

Exposure of Resource to Wrong Sphere