First published: Tue Oct 22 2019(Updated: )
A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution and a sandbox escape.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <70 | 70 |
<70 | 70 | |
Mozilla Firefox | <70.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-25136 is a vulnerability where a compromised child process can inject XBL Bindings into privileged CSS rules, allowing arbitrary code execution and a sandbox escape.
Mozilla Firefox versions up to but not including 70 are affected by CVE-2019-25136.
CVE-2019-25136 has a severity rating of high (7 out of 10).
Updating Mozilla Firefox to version 70 or higher will fix CVE-2019-25136.
More information about CVE-2019-25136 can be found at the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1530709), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2019-34/).