Mozilla Issues Emergency Zero-Day Firefox Patch

Mozilla switched to a Chrome-like release schedule years back and has kept up a consistent release cycle ever since. It doesn’t usually deviate unless there’s a serious issue. Well, there’s a serious issue. Mozilla advises all Firefox users to update to the latest version of the browser as soon as possible. The company has just become aware of a zero-day exploit affecting Firefox, meaning there are nefarious internet forces actively using it.
The latest build and the only one that will protect you from the bug is v67.0.3. You can see which version you’re running by opening the menu, clicking Help, and selecting “About Firefox.” The browser should prompt users to update, but you can do so manually if your browser is not on the latest build — just type “update” in the search bar.
According to Mozilla, the issue is a type confusion vulnerability related to JavaScript. A malicious website can use this to cause an “exploitable crash.” This could let the attacker execute remote code on the system, but they’d still be limited to the browser’s sandbox. That might be enough to do some damage, though.
Mozilla has specifically avoided providing extensive details of the flaw. It only says it knows there are active attacks in the wild, so it probably wants to get users updated first. Otherwise, it could make things even worse.

The original bug report comes from Samuel Groß, who works on Google’s elite Project Zero team, as well as the Coinbase security team. We don’t know much about the nature of the attacks, but Groß’s involvement suggests they may be attempting to exploit the vulnerability to steal cryptocurrency. A UXSS (universal cross-site scripting) coupled with the new JavaScript attack could get them what they need without touching the underlying operating system.
Firefox has managed to avoid frequent emergency updates. The last one was in 2016 when it patched a zero-day exploit that could de-anonymize users of the Tor network.
Continue reading

Remote-Control Firefighting Tank, Other Projects Receive Millions in 5G Grants
The Australian government announced late last year it would be providing organizations with up to $2 million AUD each in grants for 5G projects. Now it has revealed the winners.

Firefox 91 Circumvents Windows Browser Default Protections
Firefox has quietly implemented a new feature to switch your defaults without digging around in the Windows settings. How long that will last is anyone's guess.

Post-Quantum Firefox 58 Packs Additional Multi-Threading
Firefox Quantum launched a few months ago and impressed us with its performance and capabilities. Now FF 58 is here to smooth off a few rough edges and add some performance improvements of its own.

Firefox Add-On Protects You From Facebook Tracking
Mozilla is looking to shield users from Facebook's snooping and score some good will at the same time.