CVE-2025-2857

🟠 Łataj w tym tygodniu

W Firefox na Windows błąd IPC pozwala na ucieczkę z piaskownicy przez uzyskanie potężnego uchwytu.

CVSS
10.0
EPSS
1.9%
Exploit
none
Vendor
mozilla
Opis źródłowy (NVD)

Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sandbox escape. The original vulnerability was being exploited in the wild. *This only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 136.0.4, Firefox ESR 128.8.1, and Firefox ESR 115.21.1.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS10.0
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)1.9%
Opublikowano (NVD)2025-03-27 14:15:55 UTC
Ostatnia modyfikacja (NVD)2026-09-30 19:10:01 UTC
Referencje