CVE-2025-1930: AudioIPC StreamData could trigger a use-after-free in the Browser process
On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-1930?
CVE-2025-1930 is considered a high-severity vulnerability due to its potential to enable sandbox escapes on Windows.
How do I fix CVE-2025-1930?
To fix CVE-2025-1930, update Mozilla Firefox to version 136 or upgrade Firefox ESR to version 128.8 or 115.21.
What software is affected by CVE-2025-1930?
CVE-2025-1930 affects Mozilla Firefox versions up to 136 and Firefox ESR versions up to 115.21 and 128.8.
What kind of vulnerability is CVE-2025-1930?
CVE-2025-1930 is a use-after-free vulnerability that can occur due to bad StreamData sent over AudioIPC.
Can CVE-2025-1930 lead to remote code execution?
Yes, CVE-2025-1930 could potentially allow an attacker to execute arbitrary code due to sandbox escape capabilities.