Firefox 136.0.4 Release Notes (www.mozilla.org)
from neme@lemm.ee to firefox@fedia.io on 27 Mar 14:13
https://lemm.ee/post/59609910

#firefox

threaded - newest

kbal@fedia.io on 27 Mar 14:57 collapse

Attackers were able to confuse the parent process into leaking handles into unpriviled child processes leading to a sandbox escape. The original vulnerability was being exploited in the wild.

This only affects Firefox on Windows. Other operating systems are unaffected.