“By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation,” Mozilla explained in their advisory. Security researchers identified multiple critical flaws that could allow attackers to escalate privileges or bypass security mechanisms, prompting this significant security update, which was released on April 29, 2025. Mozilla has released Firefox 138, addressing several high-severity security vulnerabilities while introducing long-awaited features, including improved profile management. The most concerning issues include a privilege escalation vulnerability, a memory corruption flaw, and a process isolation bypass. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. The Mozilla Foundation Security Advisory details four high-impact vulnerabilities remediated in this release. CISA stated in its advisory that “There are currently no reports of these vulnerabilities being exploited in the wild,” but it recommended that users apply updates immediately after appropriate testing. Another significant vulnerability, CVE-2025-4083, reported by Nika Layzell, involved a process isolation bypass using URI links in cross-origin frames. This vulnerability stemmed from improper handling of javascript: URIs, potentially allowing content to execute in the top-level document’s process instead of the intended frame, which could enable a sandbox escape. In addition to the standard Firefox release, Mozilla has updated Firefox ESR to versions 115.23 and 128.10 with the same security fixes. This feature allows users to create separate profiles to compartmentalize their browsing activities, keeping bookmarks, tabs, passwords, and browsing history segregated between different usage contexts. Gurubaran is a co-founder of Cyber Security News and GBHackers On Security.
This Cyber News was published on cybersecuritynews.com. Publication date: Wed, 30 Apr 2025 10:00:26 +0000