Mozilla warns Windows users of critical Firefox sandbox escape flaw
ID: a3582239-7761-573a-81fe-4972183499cd
STIX ID: report--a3582239-7761-573a-81fe-4972183499cd
Feed Name: Bleeping Computer
Threat Score
Mozilla released Firefox 136.0.4 and ESR updates to fix a critical Windows sandbox escape (CVE-2025-2857). The advisory links the flaw to patterns observed in a recently exploited Chrome zero-day (CVE-2025-2783) used in an espionage campaign dubbed Operation ForumTroll, and references earlier zero-days chained with privilege escalation to install backdoors; administrators should apply the Firefox and ESR updates on Windows immediately to mitigate the active sandbox escape risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
