Crocodilus Malware Exploits Android Devices to Steal Crypto – Active IOCs
March 31, 2025Amadey Botnet – Active IOCs
March 31, 2025Crocodilus Malware Exploits Android Devices to Steal Crypto – Active IOCs
March 31, 2025Amadey Botnet – Active IOCs
March 31, 2025Severity
High
Analysis Summary
CVE-2025-2857
Mozilla Firefox could allow a remote attacker to bypass security restrictions, caused by an incorrect handle. The attacker could confuse the parent process into leaking handles into unprivileged child processes. An attacker could exploit this vulnerability to escape the browser’s sandbox and execute arbitrary code on affected systems.
Impact
- Security Bypass
Indicators of Compromise
CVE
CVE-2025-2857
Affected Vendors
Affected Products
- Mozilla Firefox - 136.0.3
- Mozilla Firefox ESR - 115.21.0
- Mozilla Firefox ESR - 128.8.0
Remediation
Refer to Mozilla Security Advisory for patch, upgrade, or suggested workaround information.