CVE-2019-25136: Mozilla Firefox
Critical severity, CVSS 10.0. EPSS: 0.7% chance of exploitation in the next 30 days.
A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution and a sandbox escape. This vulnerability affects Firefox < 70.
Affected products
- Mozilla Firefox: before 70.0 (fixed in 70.0)
Published 2023-06-19. Last modified 2026-06-17.