Sunday, November 24, 2024
HomeFirefoxAlert!! Critical Firefox Zero-Day Vulnerability Actively Exploit by Hackers in Wide -...

Alert!! Critical Firefox Zero-Day Vulnerability Actively Exploit by Hackers in Wide – Update Firefox Now

Published on

Mozilla released a security update for a critical zero-day vulnerability that affects the Firefox browser and the vulnerability fixed in 72.0.1 and Firefox ESR 68.4.1.

The vulnerability affects both Firefox, Firefox ESR and the successful exploitation of the vulnerability could lead an attacker to execute the malicious code remotely or trigger to crashes on machines that running with vulnerable Firefox versions.

The critical zero-day vulnerability was initially discovered by Qihoo 360 ATA researchers and the bug can be tracked as CVE-2019-11707.

- Advertisement - SIEM as a Service

The bug Affects Web browsers IonMonkey type confusion with StoreElementHole and FallibleStoreElement, Mozilla said.

IonMonkey is the JavaScript Just-In-Time (JIT) compiler for SpiderMonkey (Mozilla’s JavaScript engine).

It indicates that the attackers attempt to exploit a Type Confusion vulnerability and it can be triggered when incorrect alias information in IonMonkey JIT compiler for setting array elements.

Type confusion vulnerability occurs when a piece of code doesn’t verify the type of object that is passed to it and it could lead to exploit this vulnerability by tricking a user into visiting a malicious web page and execute arbitrary code within the context of the application.

This new Firefox Zero-Day vulnerability affects the browsers Just in Time Compiler and it is currently used for targeted attacks in the wild.

Since the further detailed information was not available at the time, we have reached Qihoo 360 for further information about the exploitation for this Firefox zero-day vulnerability but there is no response at the time of writing.

Mozilla released Firefox 72.0.1 and Firefox ESR 68.4.1. You can download the new Firefox version for all platform here

While this Firefox Zero-Day vulnerability was exploited in targeted attacks, Firefox users are advised to upgrade as soon as possible.

Also Read: Hackers Exploit Android Vulnerability to Install Malware Without User Interaction Via Google Play

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Nearest Neighbor Attacks: Russian APT Hack The Target By Exploiting Nearby Wi-Fi Networks

Recent research has revealed that a Russian advanced persistent threat (APT) group, tracked as...

240+ Domains Used By PhaaS Platform ONNX Seized by Microsoft

Microsoft's Digital Crimes Unit (DCU) has disrupted a significant phishing-as-a-service (PhaaS) operation run by...

Russian TAG-110 Hacked 60+ Users With HTML Loaded & Python Backdoor

The Russian threat group TAG-110, linked to BlueDelta (APT28), is actively targeting organizations in...

Earth Kasha Upgraded Their Arsenal With New Tactics To Attack Organizations

Earth Kasha, a threat actor linked to APT10, has expanded its targeting scope to...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

FortiClient VPN Flaw Enables Undetected Brute-Force Attacks

A design flaw in the logging mechanism of Fortinet's VPN servers has been uncovered,...

macOS WorkflowKit Race Vulnerability Allows Malicious Apps to Intercept Shortcuts

A race condition vulnerability in Apple's WorkflowKit has been identified, allowing malicious applications to...

Trend Micro Deep Security Vulnerable to Command Injection Attacks

Trend Micro has released a critical update addressing a remote code execution (RCE) vulnerability...