Critical Firefox Flaw CVE-2025-2857 Lets Attackers Escape Sandbox
Red | Vulnerability Report
Download PDFCVE-2025-2857 is a critical vulnerability in Mozilla Firefox for Windows, with a maximum CVSS score of 10.0. It allows a compromised child process to exploit the IPC system and escape the browser’s sandbox, potentially leading to remote code execution. The flaw affects Firefox versions before 136.0.4 and ESR versions before 128.8.1 and 115.21.1, with no impact on other operating systems. Although similar to a Chrome bug that was exploited in the wild, there is no evidence that this Firefox vulnerability has been actively used in attacks.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox