Critical Firefox, Tor Browser sandbox escape flaw fixed (CVE-2025-2857)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-2783 | Sandbox Escape via Mojo Handle Flaw in Google Chrome on Windows (CVE-2025-2783) CVE-2025-2783 is a high-severity sandbox escape in Google Chrome on Windows, caused by an incorrect handle being provided in unspecified circumstances in Mojo, Chrome's inter-process communication layer. It is triggered remotely through a malicious file and requires user interaction; an attacker who has code running inside Chrome's sandboxed renderer can abuse the handle flaw to break out of the Windows sandbox and gain broader access to the host (CVSS scope change with high impact to confidentiality, integrity, and availability). All Google Chrome versions on Windows prior to 134.0.6998.177 are affected, per the vendor fix referenced by CISA. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-27, and related reporting links it to active exploitation in the ForumTroll APT's phishing campaign against Russian scholars using fake eLibrary emails; ransomware use is unknown. No public proof-of-concept is known, and EPSS assigns a 9.2% probability of exploitation within 30 days (95th percentile). Do: Update Google Chrome on Windows to 134.0.6998.177 or later immediately and verify deployed browser versions across endpoints; the flaw is in the CISA KEV catalog, so federal agencies must apply vendor mitigations per BOD 22-01 timelines. Because exploitation is tied to malicious files delivered via phishing (e.g., the ForumTroll fake-eLibrary campaign), prioritize patching for users who open untrusted attachments and links, and hunt for associated phishing emails. | 8.3 | 9% | KEV |
| massbillions of users (Chrome is the world's dominant browser; the Windows-only subset is still likely well over 1 billion) | |
| CVE-2025-2857 | Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sandbox escape. The original vulnerability was being exploited in the wild. *This only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 136.0.4, Firefox ESR 128.8.1, and Firefox ESR 115.21.1. NVD description · AI analysis pending | 10.0 | 2% |
| — |
Full article310 words · extracted from helpnetsecurity.com · click to collapse
Google’s fixing of CVE-2025-2783, a Chrome zero-day vulnerability exploited by state-sponsored attackers, has spurred Firefox developers to check whether the browser might have a similar flaw – and they found it.
There’s currently no indication that the Firefox bug (CVE-2025-2857) is under active exploitation, but this should not be surprising: according to Statcounter, Chrome is used by 66.3% of internet users worldwide and Firefox only by 2.62%.
About CVE-2025-2857
CVE-2025-2783 has been described as “a logical error at the intersection of Google Chrome’s sandbox and the Windows operating system” by the Kaspersky researchers who flagged it, and was found in Mojo, Chromium’s inter-process communication (IPC) framework.
CVE-2025-2857 was similarly discovered in Firefox’s IPC code, and allowed a compromised child process to make the parent process “return an unintentionally powerful handle, leading to a sandbox escape.”
Mozilla has fixed CVE-2025-2857 in Firefox v136.0.4, Firefox Extended Support Release (ESR) v128.8.1, and Firefox ESR v115.21.1 for Windows. And, since the Tor Browser is built from a modified version of Firefox ESR, the Tor Project has also released an emergency security update (v14.0.8) for Windows users and advised them to update immediately.
Opera browser developers have already backported the security patch for CVE-2025-2783.
Like Opera, Microsoft Edge, the Brave and Vivaldi browsers are also based on Chromium code, and will likely receive a patch for CVE-2025-2783 soon.
Kaspersky researchers said that CVE-2025-2783 initially left them scratching their heads: “Without doing anything obviously malicious or forbidden, it allowed the attackers to bypass Google Chrome’s sandbox protection as if it didn’t even exist.”
They also noted that CVE-2025-2783 was exploited in conjuction with another vulnerability that allowed attackers to achieve remote code execution, but this flaw remains a mystery for now. The researchers have promised to publish a detailed report with technical details about the CVE-2025-2783 exploit, the malware and techniques used by the attackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/03/28/critical-firefox-tor-browser-sandbox-escape-flaw-fixed-cve-2025-2857/