What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Mozilla fixed CVE-2025-2857 in Firefox for Windows, and its March 27, 2025 advisory said the flaw was being exploited in the wild. Update to Firefox 136.0.4, Firefox ESR 128.8.1, Firefox ESR 115.21.1, or a later supported release, depending on your release channel.

What is CVE-2025-2857?

CVE-2025-2857 is a critical vulnerability in Firefox’s inter-process communication (IPC) code. Mozilla says a compromised child process could cause the parent process to return an “unintentionally powerful handle,” allowing the attacker to escape Firefox’s sandbox. The issue affects Firefox on Windows; Mozilla says other operating systems are unaffected.

Mozilla’s MFSA 2025-19 security advisory, published March 27, 2025, says the original vulnerability was being exploited in the wild. The advisory does not identify an attacker or provide a numeric CVSS score.

Which Firefox versions fix the vulnerability?

Release channel Fixed version What to do
Standard Firefox 136.0.4 Update to 136.0.4 or a later supported release.
Firefox ESR 128.8.1 Update to 128.8.1 or a later supported release on that ESR line.
Firefox ESR 115.21.1 Update to 115.21.1 or a later supported release on that ESR line.

These are the fixed builds Mozilla listed in the advisory. To check your installed version, open Firefox’s menu, select Help, then About Firefox. Firefox checks for updates there; install any offered update and restart the browser. In managed environments, administrators can confirm versions through enterprise inventory.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)

Does the sandbox escape mean Firefox had a complete remote-code-execution exploit?

The escape is an important step in getting beyond the restrictions on web content running in a tab, but it does not by itself establish a complete attack chain. Mozilla’s security blog explains that “another bug (a sandbox escape) is required to break out of the current tab and gain wider system access.” The advisory does not publish a complete remote-code-execution chain or a proof of concept for CVE-2025-2857. The available sources also do not give an estimate of how many users were affected.

What should Windows users and IT administrators do?

For individual users

  1. Open Firefox and go to Menu → Help → About Firefox.
  2. Check the version shown. If it is earlier than the applicable fixed version for your release channel, let Firefox download the update.
  3. Restart Firefox if prompted, then reopen About Firefox to verify the installed version.

For organizations

Identify Windows devices running Firefox, determine whether each installation uses standard Firefox or ESR, and verify versions through enterprise inventory. Deploy the relevant fixed build through your established patch-management process, then confirm installation. Mozilla’s Firefox enterprise deployment guidance covers centralized deployment options.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Are Firefox users on macOS or Linux affected?

Mozilla identifies the vulnerability as Windows-only and says other operating systems are unaffected. The fixed-version guidance above applies to Windows Firefox installations.

Quick Recap

Bestseller No. 1
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
Made in USA - Proudly produced in Ohio by a Veteran-owned business
$22.99
Bestseller No. 2
Bestseller No. 3
BookFactory Security Incident Report Log Book, Wire-O, 100 Pages
BookFactory Security Incident Report Log Book, Wire-O, 100 Pages
Made in USA - Proudly produced in Ohio by a Veteran-owned business; Wire-O, 100 Pages, Dimensions 3.5" x 5.25"
$9.99
Rank #3
BookFactory Security Incident Report Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • This BookFactory log book is for security guards in any sector or business. You can report location, circumstances and report number.
  • There are spaces to log the individual's names address, description and other identifying information. There are also spaces to note others involved, notes, and vehicle information if one was involved
  • Wire-O, 100 Pages, Dimensions 3.5" x 5.25"
  • Reorder SKU: LOG-100-M3CW-PP(Security-Report)

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.