Skip to content

Secure IT

Stay Secure. Stay Informed.

Primary Menu
  • Home
  • Sources
    • Krebs On Security
    • Security Week
    • The Hacker News
    • Schneier On Security
  • Home
  • Security Week
  • Firefox Affected by Flaw Similar to Chrome Zero-Day Exploited in Russia
  • Security Week

Firefox Affected by Flaw Similar to Chrome Zero-Day Exploited in Russia

Eduard Kovacs March 28, 2025
0

Mozilla says Firefox developers have determined that their browser is affected by a critical vulnerability that is similar to the Chrome zero-day disclosed a few days ago.

On Tuesday, Google announced a Chrome update that patches CVE-2025-2783, a vulnerability reported to the tech giant by cybersecurity firm Kaspersky, whose researchers saw it being exploited in attacks aimed at Russian organizations.

Kaspersky said CVE-2025-2783 has been exploited since at least mid-March by what is likely a state-sponsored threat actor to escape Chrome’s sandbox. The exploit chain also targeted another vulnerability (which Kaspersky was unable to identify) to achieve remote code execution. 

The campaign, which the security firm dubbed Operation ForumTroll because it used fake invitations to a scientific forum as a lure, targeted media outlets, educational institutions and government organizations in Russia.

Firefox developers have analyzed CVE-2025-2783 and found that a similar pattern also exists in their IPC code.

The issue, described as an incorrect handle, can allow a compromised child process to cause the parent process to “return an unintentionally powerful handle, leading to a sandbox escape”, Firefox developers said.

In the case of Firefox, the vulnerability is tracked as CVE-2025-2857. The flaw only impacts Firefox for Windows and it has been patched with the release of versions 136.0.4, 128.8.1 (ESR), and 115.21.1 (ESR).

Mozilla noted that the original vulnerability has been exploited in the wild, but did not mention anything about attacks aimed at Firefox users. 

Advertisement. Scroll to continue reading.

The Tor browser, which is based on Firefox, has also been updated to address the vulnerability.

The cybersecurity agency CISA on Thursday added the Chrome flaw to its Known Exploited Vulnerabilities (KEV) catalog. The agency noted that other Chromium-based browsers may also be affected, including Microsoft Edge and Opera. Microsoft does not appear to have issued an advisory.

The exploitation of Firefox vulnerabilities is not as common as the exploitation of Chrome bugs, but there have been roughly a dozen security holes exploited over the past decade. One example came to light in late November 2024, when ESET reported that a Russian APT had chained Firefox and Windows zero-days to deploy a backdoor.

Related: Chrome 134, Firefox 136 Patch High-Severity Vulnerabilities

Related: Chrome 133, Firefox 135 Updates Patch High-Severity Vulnerabilities

Related: Chrome 133, Firefox 135 Patch High-Severity Vulnerabilities

About The Author

Eduard Kovacs

See author's posts

Original post here

Continue Reading

Previous: PJobRAT Malware Campaign Targeted Taiwanese Users via Fake Chat Apps
Next: Product Walkthrough: How Datto BCDR Delivers Unstoppable Business Continuity

Trending Now

ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices mm.jpg 1

ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices

May 23, 2025
300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide ransomware.jpg 2

300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide

May 23, 2025
SafeLine WAF: Open Source Web Application Firewall with Zero-Day Detection and Bot Protection safeline.jpg 3

SafeLine WAF: Open Source Web Application Firewall with Zero-Day Detection and Bot Protection

May 23, 2025
U.S. Dismantles DanaBot Malware Network, Charges 16 in $50M Global Cybercrime Operation botnet.jpg 4

U.S. Dismantles DanaBot Malware Network, Charges 16 in $50M Global Cybercrime Operation

May 23, 2025
CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs saas.jpg 5

CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs

May 23, 2025
GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts prompt.jpg 6

GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts

May 23, 2025

Related Stories

Cybersecurity_News-SecurityWeek.jpg
  • Security Week

Insurance Firm Lemonade Says API Glitch Exposed Some Driver’s License Numbers

Ionut Arghire April 15, 2025 0
ransomware.jpeg
  • Security Week

Kidney Dialysis Services Provider DaVita Hit by Ransomware

Ionut Arghire April 15, 2025 0
Cybersecurity_News-SecurityWeek.jpg
  • Security Week

Conduent Says Names, Social Security Numbers Stolen in Cyberattack

Ionut Arghire April 15, 2025 0
Cybersecurity_News-SecurityWeek.jpg
  • Security Week

2.6 Million Impacted by Landmark Admin, Young Consulting Data Breaches

Ionut Arghire April 15, 2025 0
VC-Funding_China-tech.jpg
  • Security Week

China Pursuing 3 Alleged US Operatives Over Cyberattacks During Asian Games

Associated Press April 15, 2025 0
Satellite-Link-Cybersecurity.jpg
  • Security Week

Blockchain, Quantum, and IoT Firms Unite to Secure Satellite Communications Against Quantum Threats

Kevin Townsend April 15, 2025 0

Connect with Us

Social menu is not set. You need to create menu and assign it to Social Menu on Menu Settings.

Trending News

ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices mm.jpg 1
  • The Hacker News

ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices

May 23, 2025
300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide ransomware.jpg 2
  • The Hacker News

300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide

May 23, 2025
SafeLine WAF: Open Source Web Application Firewall with Zero-Day Detection and Bot Protection safeline.jpg 3
  • The Hacker News

SafeLine WAF: Open Source Web Application Firewall with Zero-Day Detection and Bot Protection

May 23, 2025
U.S. Dismantles DanaBot Malware Network, Charges 16 in $50M Global Cybercrime Operation botnet.jpg 4
  • The Hacker News

U.S. Dismantles DanaBot Malware Network, Charges 16 in $50M Global Cybercrime Operation

May 23, 2025
CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs saas.jpg 5
  • The Hacker News

CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs

May 23, 2025
GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts prompt.jpg 6
  • The Hacker News

GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts

May 23, 2025
Oops: DanaBot Malware Devs Infected Their Own PCs Oops: DanaBot Malware Devs Infected Their Own PCs 7
  • Uncategorized

Oops: DanaBot Malware Devs Infected Their Own PCs

May 22, 2025

You may have missed

mm.jpg
  • The Hacker News

ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices

[email protected] The Hacker News May 23, 2025 0
ransomware.jpg
  • The Hacker News

300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide

[email protected] The Hacker News May 23, 2025 0
safeline.jpg
  • The Hacker News

SafeLine WAF: Open Source Web Application Firewall with Zero-Day Detection and Bot Protection

[email protected] The Hacker News May 23, 2025 0
botnet.jpg
  • The Hacker News

U.S. Dismantles DanaBot Malware Network, Charges 16 in $50M Global Cybercrime Operation

[email protected] The Hacker News May 23, 2025 0
Copyright © 2025 All rights reserved. | MoreNews by AF themes.