News
If you use Firefox, this matters: this update fixes a previously unknown vulnerability
A critical Firefox update fixes a sandbox escape vulnerability similar to Chrome’s. Only Windows users are affected. Update now to stay protected.

- March 28, 2025
- Updated: July 1, 2025 at 10:02 PM

A serious security vulnerability has been discovered and patched in Mozilla Firefox, echoing a recent Chrome zero-day issue. This flaw, if exploited, could allow attackers to escape the browser’s sandbox and run malicious code on a victim’s machine. While Google’s Chrome vulnerability (CVE-2025-2783) was already being used in the wild, Mozilla’s similar bug (CVE-2025-2857) was quietly fixed before any known exploitation.
Firefox’s IPC bug mirrors Chrome’s zero-day
Mozilla developers identified a flaw in Firefox’s IPC (inter-process communication) code, where a compromised child process could force the parent to return a powerful handle. This effectively breaks out of the browser’s sandbox—a key security barrier designed to isolate web content from the rest of the system.
The sandbox is critical to preventing malicious websites from accessing user data or interfering with the operating system. Escaping it gives attackers an open door to install malware or spy on users, making this a high-risk flaw.
The patch and what users need to do
Mozilla has issued a patch and urges users to update immediately to Firefox 136.0.4, Firefox ESR 128.8.1, or ESR 115.21.1. The issue only affects Firefox on Windows; macOS and Linux users are not impacted.
Although the Chrome vulnerability was actively exploited in a campaign dubbed Operation ForumTroll, targeting Russian users via phishing, there’s no evidence yet that the Firefox flaw was abused. However, both bugs share a concerning resemblance, raising alarms across the cybersecurity community.
Users should not delay updating their browsers, as the window for potential attacks remains open for those on older versions.
Latest from Agencias
- The series returns where you will see Idris Elba like you have never seen him before
- London will be the chosen city for the next installment of the most romantic saga in cinema
- Milly Alcock debuts as Supergirl in this trailer, and the role seems designed for her
- Do you want 'Kingdom Hearts 4'? One of the voice actresses from the saga is also looking forward to it
You may also like
NewsChatGPT achieves a 76% increase in its performance
Read more
News'Clair Obscur: Expedition 33' cost a complete fortune, but it's wildly successful
Read more
NewsHelldivers 2 is getting ready to receive its biggest update to date
Read more
NewsThe Game Awards crowned the game of the year last night amid huge controversies
Read more
NewsThe most shocking news from The Games Awards 2025
Read more
NewsThe series returns where you will see Idris Elba like you have never seen him before
Read more