Mozilla Releases Security Updates for Firefox


Mozilla has released security updates to address one critical vulnerability in Firefox and Firefox ESR. Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in Firefox’s Inter-process Communication (IPC) code.

A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sandbox escape. Exploitation of original Google Chrome vulnerability CVE-2025-2783: Google has observed exploitation of CVE-2025-2783 in the wild. More information can be found in Cyber Alert CC-4639

Read more…
Source: NHS Digital


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Defending against an active threat to Siemens S7 Series PLCs

    August 19, 2026

    This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as ...

  • CISA gives feds 3 days to fix actively exploited Ray RCE bug

    August 18, 2026

    CISA says attackers are exploiting a critical 2025 vulnerability in Ray, the widely used open source framework for scaling Python and machine-learning workloads. Tracked as CVE-2025-62593 and rated 9.4 under CVSS v4, the bug was first disclosed in November 2025. It allows an attacker to use Firefox or Safari to achieve remote code execution (RCE) on a vulnerable Ray system. The open ...

  • Update your Mac: Screen Sharing vulnerability exploited in the wild

    August 17, 2026

    The Dutch National Cyber Security Centre (NCSC) issued a warning after being notified of several incidents where a vulnerability in Apple’s Screen Sharing feature was exploited to install Monero cryptominers. The vulnerability, tracked as CVE-2026-65400, was patched by Apple on August 6. It is an authentication-bypass flaw in macOS Screen Sharing that can let an attacker on the network connect ...

  • Researchers find ultimate Windows kill switch which can disable antivirus with almost no user interaction

    August 14, 2026

    Microsoft has recently fixed a vulnerability that allowed threat actors to bypass advanced security measures, disable antivirus software, and expose the target device to full system takeover. All of this, it seems, could have been possible with a very simple script, and a single click from the victim’s side. Luckily, the vulnerability was discovered by white hat hackers, ...

  • Patch Tuesday: Update now to fix 421 flaws, including three zero-days

    August 12, 2026

    Microsoft’s August 2026 Patch Tuesday addresses 421 Microsoft vulnerabilities, including 62 rated Critical. One Windows vulnerability has been exploited in the wild by the Lazarus group to gain SYSTEM privileges. The August update is smaller than July’s record-breaking release, but it’s still among Microsoft’s largest Patch Tuesday batches. More importantly, it includes several flaws likely to attract attacker interest: ...

  • The CEVA Logistics data breach is having major knock-on effects across Europe – here’s what we know

    August 11, 2026

    CEVA Logistics, one of the biggest shipping and logistics companies in the world, has suffered a major cyberattack, the effects of which are trickling down to many of its clients. The details of the hack itself, however, are not yet publicly available and what little information is out there came from the affected clients themselves. CEVA has ...