Vulnerability Intelligence Report
Incorrect handle could lead to sandbox escapes
CVE-2025-2857
Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sandbox escape. The original vulnerability was being exploited in the wild. *This only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 136.0.4, Firefox ESR 128.8.1, and Firefox ESR 115.21.1.
No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:1.87%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-668 ↗CWE-668 Exposure of Resource to Wrong Sphere
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Mozilla | Firefox | 115.21.1 <= 115.* (unaffected), 128.8.1 <= 128.* (unaffected), 136.0.4 <= * (unaffected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.872%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Mozilla Corporation · Vendor · USA |
| Reserved | 2025-03-27T10:54:42 |
| Published | 2025-03-27T13:27:57 |
| Last Updated | 2026-06-09T16:23:02 |
Community Chatter & Buzz