Mozilla Firefox Sandbox Escape Vulnerability on Windows

Vulnerability

A vulnerability allowing sandbox escape has been identified in Mozilla Firefox on Windows. A compromised child process could manipulate the parent process into granting an unintentionally powerful handle, similar to a recent vulnerability in Google Chrome (CVE-2025-2783). This issue affects Firefox versions prior to 136.0.4, as well as Firefox ESR versions prior to 128.8.1 and 115.21.1.

Impact

Exploitation of this vulnerability allows a child process to escape its sandbox, potentially leading to unauthorized access or actions within the parent process.

Remediation

Users can upgrade to Firefox 136.0.4, Firefox ESR 128.8.1, or Firefox ESR 115.21.1 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
10.0
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.