Mozilla released a security advisory addressing a critical vulnerability in Firefox, identified as CVE-2025-12380, which affects versions prior to 144.0.2. The flaw allows a compromised child process to trigger a use-after-free condition in the GPU or browser process via WebGPU-related IPC calls, potentially enabling sandbox escape. Security researchers have rated this vulnerability as critical (CVSS 9.8), and it is remotely exploitable, posing a significant risk to users of affected Firefox versions.
The Canadian Centre for Cyber Security and other sources have urged users and administrators to review the official Mozilla security advisories and apply the necessary updates immediately to mitigate the risk. The vulnerability highlights the importance of timely patching, especially for widely used browsers like Firefox, to prevent exploitation by threat actors targeting browser sandboxing mechanisms.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Mozilla published a security advisory for CVE-2025-12380, a use-after-free vulnerability in Firefox's WebGPU IPC handling that could allow a sandbox escape. The advisory was also reflected in related government and vulnerability-tracking notices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.