CVE-2025-3032EPSS p31.3%
CVE-2025-3032CVE-2025-3032
mozilla / firefox
Description
Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability was fixed in Firefox 137 and Thunderbird 137.
Scoring
| CVSS | 7.4 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 0.39% probability of exploitation · percentile 31.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |