Mozilla Products March 2025 1st Security Update Advisory
Overview
An update has been made available to address a vulnerability in Mozilla products (Firefox, Firefox ESR versions). users of affected products are advised to update to the latest version.
Affected Products
Firefox 136.0.4
Firefox ESR 115.21.1
Firefox ESR 128.8.1 and earlier
Resolved Vulnerabilities
Critical malformed handle vulnerability in Firefox, Firefox ESR could allow a sandbox escape (CVE-2025-2857) [1]
Vulnerability Patches
The following Vulnerability Patches were made available in the 03/27/2025 update. For more information on Vulnerability Patches, please refer to the “Mozilla” Referenced Sites documentation.
Firefox 136.0.4
Firefox ESR 115.21.1
Firefox ESR version 128.8.1
Referenced Sites
[1] Security Vulnerability fixed in Firefox 136.0.4, Firefox ESR 128.8.1, Firefox ESR 115.21.1
https://www.mozilla.org/en-US/security/advisories/mfsa2025-19/
[2] Update Firefox to the latest release
https://support.mozilla.org/ko/kb/update-firefox-latest-release