Pull down to refresh stories
Courses Write Login VITi?ng Vi?t Store
Verified

Firefox Security Response to pwn2own 2025

This is why not only does Firefox have a long running bug bounty program but also mature release management and security engineering practices.

At Mozilla, we consider security to be a paramount aspect of the web. This is why not only does Firefox have a long running bug bounty program but also mature release management and security engineering practices. The useful part sits in the context, the practical impact, and what readers can use to decide the next step.

Reference image for: Firefox Security Response to pwn2own 2025

At Mozilla, we consider security to be a paramount aspect of the web. This is why not only does Firefox have a long running bug bounty program but also mature release management and security engineering practices.

What happened

These practices combined with well-trained and talented Firefox teams are also the reason why we respond to security bugs as quickly as we do. This week at the security hacking competition pwn2own, security researchers demonstrated two new content-process exploits against Firefox. Neither of the attacks managed to break out of our sandbox, which is required to gain control over the user’s system.

Where the sources line up

Out of abundance of caution, we just released new Firefox versions in response to these attacks – all within the same day of the second exploit announcement. The updated versions are Firefox 138. 0. 4, Firefox ESR 128. 10. 1, Firefox ESR 115. 23. 1 and Firefox for Android. Despite the limited impact of these attacks, all users and administrators are advised to update Firefox as soon as possible.

Practical impact for readers

Just last year at the same security event, we responded to an exploitable security bug within 21 hours , for which we earned an award as the fastest to patch . But this year was special. This year, two security researchers signed up to attack Firefox at pwn2own. We continued the same rapid security response this year too. The people who should read carefully are system admins, shop owners, content teams, and anyone holding customer data or operational accounts. In security, the next follow-up is patch speed, real adoption, and whether teams actually keep the safer behavior in place.

Who should pay attention now

Pwn2Own is an annual computer hacking contest where participants aim to find security vulnerabilities in major software such as browsers. This year, the event was held in Berlin, Germany, and a lot of popular software was listed as potential targets for security research . As part of the event preparation, we were informed that Firefox was also listed as a target. But it took until the day before the event when we learned that not just one but two groups signed up to demonstrate their work.

What is still unclear

Typically, people attacking a browser require a multi-step exploit. At first, they need to compromise the web browser tab to gain limited control of the user’s system. But due to Firefox’s robust security architecture, another bug (a sandbox escape) is required to break out of the current tab and gain wider system access. Unlike prior years, neither participating group was able to escape our sandbox this year. We have verbal confirmation that this is attributed to the recent architectural improvements to our Firefox sandbox which have neutered a wide range of such attacks. This continues to build confidence in Firefox’s strong security posture.

Source notes

Related stories

SecurityWindows 11’s next security feature may cost you gaming performanceSecurityAI-driven development lifecycle using Amazon Bedrock AgentCoreSecurityỨng dụng câu cá Fishbrain bị tấn công, lộ dữ liệu của hơn 20 triệu người dùng