First published: Tue Mar 04 2025(Updated: )
On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8.
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <136 | |
Firefox ESR | <115.21<128.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2349787 is critical due to the potential for a sandbox escape.
To fix REDHAT-BUG-2349787, update to Firefox version 136 or newer and Firefox ESR version 115.21 or 128.8 or newer.
Firefox versions below 136 and Firefox ESR versions below 115.21 and 128.8 are affected by REDHAT-BUG-2349787.
Yes, REDHAT-BUG-2349787 can be exploited remotely through bad StreamData sent over AudioIPC.
The primary systems impacted by REDHAT-BUG-2349787 are Windows running the vulnerable versions of Firefox and Firefox ESR.