CVE-2025-5687: Local privilege escalation vulnerability in Mozilla VPN clients for macOS v2.27.0 and below.
A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. This bug only affects Mozilla VPN on macOS. Other operating systems are unaffected.. This vulnerability was fixed in Mozilla VPN 2.28.0 (macOS).
Other sources
A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root.This bug only affects Mozilla VPN on macOS. Other operating systems are unaffected.
— Mozilla
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5687?
CVE-2025-5687 is a critical vulnerability that allows privilege escalation on macOS systems.
How do I fix CVE-2025-5687?
To mitigate CVE-2025-5687, users should update Mozilla VPN to version 2.29.0 or later.
Who is affected by CVE-2025-5687?
CVE-2025-5687 affects users of Mozilla VPN specifically on macOS.
Can CVE-2025-5687 be exploited remotely?
No, CVE-2025-5687 requires local access to the machine to exploit.
What is the impact of CVE-2025-5687?
The impact of CVE-2025-5687 is that a normal user could gain root privileges, compromising system security.