Critical severity9.8NVD Advisory· Published Oct 28, 2025· Updated Apr 13, 2026
CVE-2025-12380
CVE-2025-12380
Description
Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or browser process using WebGPU-related IPC calls. This may have been usable to escape the child process sandbox. This vulnerability was fixed in Firefox 144.0.2.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- bugzilla.mozilla.org/show_bug.cginvdPermissions RequiredVendor Advisory
- www.mozilla.org/security/advisories/mfsa2025-86/nvdVendor Advisory
News mentions
0No linked articles in our index yet.