Firefox beats Edge with swift response to massive browser security hole

Microsoft Edge

The existence of a nasty bug that affected the Firefox and Edge browsers has been revealed, and although the flaw has now been patched in both cases, Mozilla’s response to the issue was a far more efficient affair than Microsoft’s.

Jake Archibald, a developer advocate for Google’s Chrome browser – which wasn't impacted by the flaw – discovered the bug, which he dubbed ‘Wavethrough’, because it involves exploiting WAV audio in the browser to allow data through which shouldn't be viewable by the attacker.

And it could potentially be used to spill some alarming personal data, if the user is persuaded to visit a malicious site primed to take advantage of the vulnerability. Archibald notes that: “It means you could visit my site in Edge, and I could read your emails, I could read your Facebook feed, all without you knowing.”

Nasty indeed. The good news, as we noted at the outset, is that this has been patched in both the affected browsers – but what’s almost as interesting as the bug itself is how Mozilla and Microsoft reacted to the report of the problem.

Archibald observed that “Firefox handled this brilliantly,” – within three hours the bug had been confirmed, and Mozilla had looked into other potential similar leaks.

“I was able to engage with engineers directly on how the issue should be fixed,” Archibald added, and as the vulnerability was caught in a beta version, Mozilla patched things up before it ever made the release version of Firefox. That happened back in March.

Jumping through hoops

As for Microsoft, however, Archibald tells a very different story. He reported the bug to the firm’s security team on March 1, then had to jump through several hoops to actually get them to look at the issue, and he subsequently waited 20 days without any response.

Eventually, after some chasing, Microsoft’s security team informed Archibald that they were indeed developing a fix, but gave no further details. More waiting, and further chasing on the bug bounty – which Archibald wanted to donate to charity – ensued.

Archibald essentially observes that the whole process felt like something of a trial, and noted: “I really want Microsoft to look at the experience I had with Firefox and learn from it. Security issues like this put their users at huge risk, and they need to ensure reporting these things isn't more effort than it's worth.”

Microsoft fixed the issue in Edge in its latest round of patches earlier this month, with the severity of the update labelled as ‘important’. Indeed, Archibald provides a link in his blog post to test if the attack works on your version of Edge, and advises that you should (obviously) immediately update your browser if it does.

Microsoft has always been big on emphasizing the security of Windows 10 in general, as well as Edge, which it’s pushing hard as the operating system’s go-to browser, but as we’ve seen in the past it hasn’t always come up trumps in terms of defeating vulnerabilities or hackers.

If Archibald’s experience is anything to go by, there’s certainly some work to be done in terms of organization and communication for Microsoft’s security team.

This isn’t the first time Edge has been criticized this year in terms of a sluggish response to fixing a vulnerability, either, as we saw back in February.

Via Wccftech.com

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Browsers
Woman using a Windows computer with Microsoft Edge
Don’t panic – Microsoft’s Edge browser isn’t about to subject you to a flood of unblocked adverts (not yet, anyway)
Google Chrome browser icon
A new split-screen feature is coming to Google Chrome, and it's surprisingly powerful
The Microsoft Edge logo on a black background displayed on a laptop screen.
Microsoft just gave Edge a great new feature to ensure the browser doesn’t slow down the PC, and it’s tempting me to switch from Google Chrome
Google Chrome with Christmas theme in Windows 11
I've used Edge, Firefox, and Opera, and yet after ten years in tech journalism, I still come back to Chrome
Woman using a Windows computer with Microsoft Edge
Microsoft gets rid of ‘Edge uninstall’ advice page after facing criticism over it having nothing to do with removing the app, and just promoting the browser instead
Microsoft Edge
Sorry, you're not getting Microsoft Edge off of your PC, at least according to its new 'uninstall' document
Latest in News
Two Android phones on a green and blue background showing Google Messages
Struggling with slow Google Messages photo transfers? Google says new update will make 'noticeable difference'
Elayne, Egwene, and Nynaeve dressed regally and on horseback in The Wheel of Time season 3
'There's a reason why we do it': The Wheel of Time showrunner responds to fans who are still upset over the Prime Video show's plot alterations
Google Pixel 9
Android 16 could bring an improved Samsung DeX-style desktop mode to more phones
An Nvidia GeForce RTX 4060 Ti
Nvidia could unleash RTX 5060 and 5060 Ti GPUs on PC gamers tomorrow, but there’s no sign of rumored RTX 5050 yet
AI writing
ChatGPT just wrote the most beautiful short story, and I wonder what I'm even doing here
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit