High firefox UAF

Overview

High
Severity
CVSS
No
Exploited ITW
Embargoed
Fix Status
Impacthigh
DescriptionOn Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape.
ComponentCore
Bug ClassUAF
Tracker1902309
CISA KEVNot listed
Crediteddalmurino
Disclosed2025-03-04

Fix not yet public

No public source fix for this bug has been identified on the main branch yet — it is embargoed or not yet disclosed. Root-cause analysis is withheld until the fix commit is available.
On This Page