CVE-2025-2857Patch(mozilla / firefox)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mozilla firefox systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sandbox escape. The original vulnerability was being exploited in the wild. *This only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 136.0.4, Firefox ESR 128.8.1, and Firefox ESR 115.21.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-668

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
firefox

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-14: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-14: 104-14
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 CRITICAL: CVE-2025-2857 | CVSS 10.0 Firefox sandbox escape on Windows. Compromised child process can escalate privileges. Patch NOW: Firefox 136.0.4, ESR 128.8.1, ESR 115.21.1 Similar to exploited Chrome vuln CVE-2025-2783 #CVE #PatchNow #ThreatIntel https://t.co/RvgvAK1bMG

    Post summary

    The tweet alerts about the critical CVE‑2025‑2857 sandbox escape in Firefox for Windows and urges immediate patching, but provides no PoC, exploit code, or evidence of active exploitation.

    00000150
    25 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox---
Appmozillafirefox---

Explore more