Mozilla Responds to Critical Vulnerability: Urgent Firefox Update
ID: 1e3cd928-84a3-5c4e-8b79-e02eeedce10f
STIX ID: report--1e3cd928-84a3-5c4e-8b79-e02eeedce10f
Feed Name: SOCRadar Blog
Mozilla issued an urgent update to Firefox for Windows to patch a critical IPC handle-management vulnerability (CVE-2025-2857) that could allow a compromised child process to pass an overly permissive handle to a parent and escape the browser sandbox; fixed versions include Firefox 136.0.4 and ESR 115.21.1 / 128.8.1. The advisory notes similarity to an actively exploited Chrome zero-day (CVE-2025-2783) and recommends immediate patching, while CISA has added the Chrome issue to its KEV catalog and mandated federal updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
