logo

Mozilla warns Windows users of critical Firefox sandbox escape flaw

ID: a3582239-7761-573a-81fe-4972183499cd

STIX ID: report--a3582239-7761-573a-81fe-4972183499cd

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-03-27

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Mozilla released Firefox 136.0.4 and ESR updates to fix a critical Windows sandbox escape (CVE-2025-2857). The advisory links the flaw to patterns observed in a recently exploited Chrome zero-day (CVE-2025-2783) used in an espionage campaign dubbed Operation ForumTroll, and references earlier zero-days chained with privilege escalation to install backdoors; administrators should apply the Firefox and ESR updates on Windows immediately to mitigate the active sandbox escape risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.