logo

Mozilla Responds to Critical Vulnerability: Urgent Firefox Update

ID: 1e3cd928-84a3-5c4e-8b79-e02eeedce10f

STIX ID: report--1e3cd928-84a3-5c4e-8b79-e02eeedce10f

Feed Name: SOCRadar Blog

Threat Score
70/100

Date Published: 2025-03-28

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Mozilla issued an urgent update to Firefox for Windows to patch a critical IPC handle-management vulnerability (CVE-2025-2857) that could allow a compromised child process to pass an overly permissive handle to a parent and escape the browser sandbox; fixed versions include Firefox 136.0.4 and ESR 115.21.1 / 128.8.1. The advisory notes similarity to an actively exploited Chrome zero-day (CVE-2025-2783) and recommends immediate patching, while CISA has added the Chrome issue to its KEV catalog and mandated federal updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.