Home » Security News » Critical 0-day in Firefox is being actively exploi...

Critical 0-day in Firefox is being actively exploited; Update your browser now

Critical 0-day in Firefox is being actively exploited; Update your browser now
Deepanker Verma January 10, 2020 Security

Add Techlomedia as a preferred source on Google. Preferred Source

If you use the Firefox web browser on any desktop platform, you must update it now to be safe.

Earlier today, Mozilla released Firefox 72.0.1 and Firefox ESR 68.4.1 versions to patch a critical zero-day vulnerability that is being actively exploited by a group of hackers.

The ‘CVE-2019-17026’ is a critical ‘type confusion vulnerability’ in the IonMonkey just-in-time (JIT) compiler of SpiderMonkey JavaScript engine. It lets attackers crash the application or perform code execution. In the worst case, this vulnerability lets attackers take control of users’ computers.

Critical 0-day in Firefox

The type confusion vulnerability occurs when the code blindly uses the object without verifying it.

This vulnerability can be exploited by an attacker by tricking the user into visiting a maliciously crafted web page. As soon as the vulnerable use opens the malicious web page, it will execute arbitrary code on the system.

This patch also fixes 11 other vulnerabilities from which 6 might allow attackers to run malicious code.

The Mozilla advisory credited researchers at China-based Qihoo 360 who has not yet revealed the details of the exploit.

If you are using Firefox on any desktop platform, you need to navigate to Menu > Help > About Mozilla Firefox to manually update the browser.

Source

Follow Techlomedia on Google News to stay updated. Follow on Google News

Affiliate Disclosure:

This article may contain affiliate links. We may earn a commission on purchases made through these links at no extra cost to you.

Deepanker Verma

About the Author: Deepanker Verma

Deepanker Verma is the Founder and Editor-in-Chief of TechloMedia. He holds Engineering degree in Computer Science and has over 15 years of experience in the technology sector. Deepanker bridges the gap between complex engineering and consumer electronics. He is also a a known Security Researcher acknowledged by global giants including Apple, Microsoft, and eBay. He uses his technical background to rigorously test gadgets, focusing on performance, security, and long-term value.

Related Posts

Stay Updated with Techlomedia

Join our newsletter to receive the latest tech news, reviews, and guides directly in your inbox.