Firefox update fixes two nasty security vulnerabilities, so patch now

Firefox
Image credit: Mozilla (Image credit: Mozilla)

Mozilla has released four new updates in an attempt to patch two critical Firefox vulnerabilities that are allegedly being exploited in the wild. 

Firefox 97.0.2., Firefox ESR 91.6.1., Firefox for Android 97.3.0., and Focus 97.3.0, have been launched addressing two serious zero-day flaws.

The zero-days in question are described as “Use-after-free”, bugs which, when abused, crash the browser while giving the attacker the ability to run any commands without permission. That means a threat actor could potentially abuse the flaw to run malware, ransomware, or any other malicious code on the target endpoint. 

TechRadar needs you!

We're looking at how our readers use VPNs with different devices so we can improve our content and offer better advice. This survey shouldn't take more than 60 seconds of your time. Thank you for taking part.

>> Click here to start the survey in a new window <<

Malicious redirects

With these patches, Mozilla addressed CVE-2022-26485, and CVE-2022-26486, without going into detail on how exactly they’re being abused in the wild, aside from saying their use has been reported on. 

Whatever the case may be, users are advised to patch up immediately, to prevent falling victim. They can do that by going to Firefox menu > Help > About Firefox, where the browser will automatically look for new updates and install them. 

The updates are also available for download on these links:

Being the actual window to the internet, browsers are often in the crosshairs for hackers. Mozilla was forced to block access to two popular add-ons which had around a million users in late 2021 following reports they had been compromised. 

Bypass and Bypass XM, two add-ons that were allegedly using reverse-proxies to allow users to access paywalled content, were said to be misusing the proxy API, thus interfering with the browser’s update functionality.

As users were prevented from downloading updates for the browser, as well as from accessing updated blocklists, the add-ons placed them in harm’s way. 

 Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A building at the Microsoft Headquarters campus in Redmond, Washington (2014).
Microsoft patches worrying zero-day along with 71 other flaws
Representational image of a cybercriminal
Microsoft just patched a host of worrying security issues, so update now
Apple&#039;s new &quot;Share Item Location&quot; feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
Cyber-security
Adobe releases software updates to patch security issues
A computer being guarded by cybersecurity.
Worrying Windows security issue patched by 7-Zip, so patch now
The best free firewall
Sophos hotfixes remote code execution vulnerabilities in Firewall
Latest in Security
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
Red padlock open on electric circuits network dark red background
Aviaton firms hit by devious new polyglot malware
A laptop with a red screen with a white skull on it with the message: &quot;RANSOMWARE. All your files are encrypted.&quot;
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Image of laptop infected with malware
Ransomware criminals are now sending their demands...by snail mail?
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day