CVE-2019-25136: Mozilla Firefox

Critical severity, CVSS 10.0. EPSS: 0.7% chance of exploitation in the next 30 days.

A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution and a sandbox escape. This vulnerability affects Firefox < 70.

Affected products

  • Mozilla Firefox: before 70.0 (fixed in 70.0)

Published 2023-06-19. Last modified 2026-06-17.