Input validation error in Mozilla Firefox and Firefox ESR - CVE-2025-2857
Published: March 27, 2025 / Updated: May 30, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input within the IPC code. A remote attacker can trick the victim into visiting a specially crafted website, bypass sandbox restrictions and execute arbitrary code on the system.
Note, the vulnerability is similar to #VU106029 (CVE-2025-2783).
Affected software
Firefox ESR
How to mitigate CVE-2025-2857
Firefox ESR - addressed in versions 115.21.1, 128.8.1