Use-After-Free Vulnerability in Firefox Browser by Mozilla
CVE-2025-1930

8.8HIGH

Key Information:

Vendor
Mozilla
Vendor
CVE Published:
4 March 2025

Summary

A vulnerability exists in the Firefox browser for Windows, wherein an attacker could exploit compromised content within the browser's process. Malicious StreamData sent via AudioIPC may trigger a use-after-free condition, potentially allowing the attacker to perform a sandbox escape. This flaw affects specific versions of Firefox and Firefox Extended Support Release (ESR), highlighting the importance of timely updates to mitigate risks.

Affected Version(s)

Firefox < 136

Firefox ESR < 115.21

Firefox ESR < 128.8

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dalmurino
.