Summary

Vulnerability Name Mozilla Firefox Sandbox Escape (CVE-2025-2857)
Released on March 28, 2025
Affected Component Mozilla Firefox
Affected Version

Firefox < 136.0.4

Firefox Extended Support Release (ESR) < 115.21.1

Firefox ESR < 128.8.1

Vulnerability Type Sandbox escape
Exploitation Condition
  1. User authentication: not required.
  2. Precondition: default configurations.
  3. Trigger mode: remote.
Impact

Exploitation difficulty: easy. This vulnerability enables remote code execution without authorization.

Severity: high. This vulnerability may result in remote code execution.

Official Solution Available

Solutions

Remediation Solutions

Version Check

To view the version information, open the Mozilla Firefox browser, click the Menu icon (three horizontal lines stacked vertically) in the upper-right corner of the browser, and choose Help > About Firefox.

Official Solution

The latest version has been officially released to fix the vulnerability. Affected Windows users are advised to update Mozilla Firefox to one of the following versions as needed:

Firefox 136.0.4

Firefox ESR 115.21.1

Firefox ESR 128.8.1

Download link: https://www.mozilla.org/en-US/firefox/new/

Sangfor Solutions

Risky Asset Discovery

Sangfor Endpoint Secure can proactively detect vulnerabilities in Mozilla Firefox, and has provided a solution to discover assets vulnerable to the Mozilla Firefox Sandbox Escape (CVE-2025-2857) vulnerability in batches. The corresponding fingerprint ID is 0000322.

Timeline

On March 28, 2025, Sangfor FarSight Labs received notification of the sandbox escape vulnerability in Mozilla Firefox (CVE-2025-2857).

On March 28, 2025, Sangfor FarSight Labs released a vulnerability alert.

References

https://www.mozilla.org/en-US/security/advisories/mfsa2025-19/#CVE-2025-2857

Learn More

Sangfor FarSight Labs researches the latest cyber threats and unknown zero-day vulnerabilities, alerting customers to potential dangers to their organizations, and providing real-time solutions with actionable intelligence. Sangfor FarSight Labs works with other security vendors and the security community at large to identify and verify global cyber threats, providing fast and easy protection for customers.

Listen To This Post

Search

Related Articles

Roundup of Microsoft Patch Tuesday (October 2025)

Date : 15 Oct 2025
Read Now

Roundup of Microsoft Patch Tuesday (June 2025)

Date : 13 Jun 2025
Read Now

CVE-2025-27817: Apache Kafka Connect Arbitrary File Read

Date : 12 Jun 2025
Read Now

See Other Product

Cyber Command - NDR Platform
MDR TCO Calculator - User Input Page
Endpoint Secure
MDR TCO Calculator - Report Page
Sangfor Athena SWG - Secure Web Gateway
Sangfor Zero Trust Data Protection