KEVIntel
10.0
CVSS
Critical

CVE-2025-2857

PUBLISHED

Incorrect handle could lead to sandbox escapes

Exploited in the wild Remote Low complexity No user interaction
Vendor
Mozilla
Product
Firefox
Published
Mar 27, 2025
EPSS

Description

Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sandbox escape. The original vulnerability was being exploited in the wild. *This only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 136.0.4, Firefox ESR 128.8.1, and Firefox ESR 115.21.1.

windows

CVSS scores

CVSS v3.1 10.0 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2025-03-27 13:27:57 UTC · Source

SSVC decision points

Exploitation
none
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CVE Mar 27, 2025

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel