Firefox gets patch for critical zeroday that’s being actively exploited
arstechnica.com
arstechnica.com
Particularly interesting is this tweet which suggests there might be an accompanying unpatched vulnerability in IE: https://twitter.com/campuscodi/status/1215020566656299011
Oh dear. We also had a previous zero-day fixed around 7 months ago. But again, there are more critical bugs vs moderate ones here. It goes to show the sheer complexity of developing open-source browsers.
The problem is starting to look far more complicated than just swapping in languages, since there is a lot to think about in a browser.
And FF tells me, it cannot update automatically, i would have to download the new version.
Anyway, I'm glad that they have a mechanism to push out urgent updates like this.
"In January 2020, a Reddit user reported Qihoo's presence in Samsung mobile phones as a pre-installed storage cleaner in the device settings, from where it sends data packages to Chinese servers."
Definitely not a company one would expect to report vulnerabilities. Also odd that they would be find Firefox issues given their browser uses IE and Chrome renderers.
https://hg.mozilla.org/releases/mozilla-release/rev/8a2adb09...
Date introduced seems Thu, 02 Feb 2012 13:41:58 +0100 (2012-02-02) but I may be wrong
Good grief that's a long time.
Generally those exploit only work in particular scenarios...
A little frustrating that they don't list a fixed version for Firefox Developer Edition: 73.0b2 just came out so I guess hopefully it's okay?