{"id":"CVE-2025-2857","title":"Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code","summary":"Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle,…","severity":"critical","cvss":10,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-668"],"vendor":"mozilla","product":"firefox","affected":["firefox < 136.0.4","firefox < 115.21.1","firefox >= 128.1.0, < 128.8.1"],"patched":["firefox 128.8.1"],"published":"2025-03-27","updated":"2026-09-30","sourceUpdated":"2026-09-30T19:10:01.007","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-2857","references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1956398","label":"security@mozilla.org"},{"url":"https://issues.chromium.org/issues/405143032","label":"security@mozilla.org"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-2783","label":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2025-19/","label":"security@mozilla.org"}],"tags":["nvd"],"epss":0.01921,"epssPercentile":0.79149,"ingestedAt":"2026-09-30T19:21:07.231Z","slug":"CVE-2025-2857","body":"## Overview\n\nFollowing the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sandbox escape. \nThe original vulnerability was being exploited in the wild. \n*This only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 136.0.4, Firefox ESR 128.8.1, and Firefox ESR 115.21.1.\n\n## Affected\n\n- `firefox < 136.0.4`\n- `firefox < 115.21.1`\n- `firefox >= 128.1.0, < 128.8.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `firefox 128.8.1`","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":55,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}