CVE-2025-2857 is a sandbox escape vulnerability in Mozilla Firefox on Windows caused by incorrect handling of IPC-related handles between a compromised child process and the parent process. A malicious child process can induce the parent to return an unintentionally powerful handle, breaking the intended security boundary enforced by the browser sandbox. The issue was identified as following a similar pattern to Chrome CVE-2025-2783. The vulnerability affects Firefox for Windows prior to 136.0.4, Firefox ESR prior to 128.8.1, and Firefox ESR prior to 115.21.1. Other operating systems are not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
ChromSploit Framework is a modular, extensible exploitation and research platform focused on browser and server vulnerabilities. It provides operational exploit modules for several high-profile CVEs (including Chrome, Edge, Firefox, Tomcat, and Git), with a strong emphasis on safety: all exploits default to simulation mode, and real exploitation requires explicit authorization. The framework supports multi-stage browser exploit chains, advanced payload obfuscation, automated tunneling (ngrok), and C2 integration (Sliver, Metasploit). It includes a professional reporting system, live monitoring, and evidence collection. The repository is well-structured, with clear separation between core logic, modules, exploits, and documentation. Numerous endpoints are fingerprintable, including local HTTP servers for exploit delivery, OAuth phishing, and data exfiltration. The codebase is primarily Python, with supporting JavaScript, JSP, and shell scripts. This framework is suitable for advanced security research, red teaming, and educational demonstrations, but should only be used in authorized, isolated environments due to the presence of real exploit code (even though simulation is the default).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Firefox for Windows sandbox escape vulnerability caused by incorrect handle usage.
A vulnerability in Mozilla Firefox (CVE-2025-2857) similar to the Chrome sandbox escape, patched in version 136.0.4. It is related to the same class of issues as CVE-2025-2783.
A vulnerability in Mozilla Firefox (CVE-2025-2857) similar to the Chrome sandbox escape, details unspecified but likely related to browser sandboxing and privilege escalation.
A Firefox IPC-related vulnerability involving a similar pseudo-handle handling pattern to the Chrome sandbox escape issue, prompting a Firefox security update.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.