Firefox Zero-Day Underneath Assault: Replace Your Browser Instantly

Oct 10, 2024Ravie LakshmananVulnerability / Browser Safety

Mozilla has revealed {that a} essential safety flaw impacting Firefox and Firefox Prolonged Assist Launch (ESR) has come beneath lively exploitation within the wild.

The vulnerability, tracked as CVE-2024-9680, has been described as a use-after-free bug within the Animation timeline part.

“An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines,” Mozilla stated in a Wednesday advisory.

“We have had reports of this vulnerability being exploited in the wild.”

Cybersecurity

Safety researcher Damien Schaeffer from Slovakian firm ESET has been credited with discovering and reporting the vulnerability.

The problem has been addressed within the following variations of the online browser

  • Firefox 131.0.2
  • Firefox ESR 128.3.1, and
  • Firefox ESR 115.16.1.

There are at present no particulars on how the vulnerability is being exploited in real-world assaults and the id of the risk actors behind them.

That stated, such distant code execution vulnerabilities may very well be weaponized in a number of methods, both as a part of a watering gap assault focusing on particular web sites or via a drive-by obtain marketing campaign that tips customers into visiting bogus web sites.

Customers are suggested to replace to the newest model to remain protected towards lively threats.

Discovered this text fascinating? Comply with us on Twitter and LinkedIn to learn extra unique content material we publish.

Recent articles

5 Methods for Gathering Cyber Menace Intelligence

To defend your group towards cyber threats, you want...

CISA Warns of Lively Exploitation in SolarWinds Assist Desk Software program Vulnerability

Oct 16, 2024Ravie LakshmananVulnerability / Knowledge Safety The U.S. Cybersecurity...

Astaroth Banking Malware Resurfaces in Brazil by way of Spear-Phishing Assault

Oct 16, 2024Ravie LakshmananCyber Assault / Banking Trojan A brand...

GitHub Patches Crucial Flaw in Enterprise Server Permitting Unauthorized Occasion Entry

Oct 16, 2024Ravie LakshmananEnterprise Safety / Vulnerability GitHub has launched...