Firefox Security Response to pwn2own 2025

2026-04-15T07:24:04Z99912f93370e9e849fb3b5a03c5f3169e7ec2e20b727f5c57e216623f7cbe7f9
Cure53GPG key rotationHTTPS upgradeMRSP v3.0PKIbug bountycertificate authorityfirefoxin-the-wild exploitmixed contentmozillamozilla vpnpwn2ownrelease signingroot store policysecurity auditsecurity blogsigning keyvulnerability response

What happened

Mozilla Security Blog posts (2022–2025) covering: Firefox’s security response to pwn2own 2025 and mitigation of in-the-wild Firefox exploits; rotation/upgrade of the GPG signing subkey for Firefox release manifests; publication of Mozilla Root Store Policy (MRSP) v3.0 (effective Mar 15, 2025) with CA/PKI requirement changes; planned mixed-content HTTPS upgrades in Firefox; and a Cure53 security audit of Mozilla VPN. Items highlight release-signing key rotation, CA/root-store policy changes, ongoing active-exploit remediation, and broader hardening of Firefox and related services.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
mozilla_security_advisories
Record identifier
99912f93370e9e849fb3b5a03c5f3169e7ec2e20b727f5c57e216623f7cbe7f9
Enrichment time
2026-04-15T07:24:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.