CVE-2025-2857Critical· 10.0▾ MidnightFollowing the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle,…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 55 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.9%
Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sandbox escape. The original vulnerability was being exploited in the wild. This only affects Firefox on Windows. Other operating systems are unaffected.. This vulnerability was fixed in Firefox 136.0.4, Firefox ESR 128.8.1, and Firefox ESR 115.21.1.
firefox < 136.0.4firefox < 115.21.1firefox >= 128.1.0, < 128.8.1Upgrade past the affected range:
firefox 128.8.1Connected by shared product, vendor, weakness, or advisory.
CVE-2023-29538Medium· 4.3Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request
CVE-2026-96869Medium· 4.3Information disclosure in the Networking component
CVE-2026-100832High· 8.8Use-after-free in the Graphics: Canvas2D component
CVE-2026-100831High· 8.8Use-after-free in the DOM: UI Events & Focus Handling component
CVE-2026-100830NoneMitigation bypass in the DOM: Navigation component
CVE-2026-100829NoneMitigation bypass in the DOM: Security component