27 C
Jaipur
Sunday, October 25, 2020

Critical FireFox Zero-Day Vulnerability Activily Exploit by Hackers

Must read

Netflix’s Blood of Zeus is no Castlevania, but it should tide you over until season 4

Honestly, I was pretty thrilled when Netflix announced Blood of Zeus. A mature anime miniseries, drawing on Greek mythology, made by the studio behind...

Lenovo Legion Phone Duel, a bizarre new gaming phone, is available to buy now

If you're looking to buy a new gaming phone the Lenovo Legion Phone Duel is out today, and it might be great for the...

Packers vs Texans live stream: how to watch NFL week 7 online from anywhere

The Green Bay Packers roll into week 7 with an impressive 4-1 record and all signs point to that becoming 5-1 after today's game...

Steelers vs Titans live stream: how to watch NFL week 7 online from anywhere

Two of the NFL’s three remaining undefeated teams do battle at Heinz Field today in the pick of week 7's games. After a three-week...

Mozilla released a security update for a critical zero-day vulnerability that affects the Firefox browser and the vulnerability fixed in 72.0.1 and Firefox ESR 68.4.1.

The vulnerability affects both Firefox, Firefox ESR and the successful exploitation of the vulnerability could lead an attacker to execute the malicious code remotely or trigger to crashes on machines that running with vulnerable Firefox versions.

The critical zero-day vulnerability was initially discovered by Qihoo 360 ATA researchers and the bug can be tracked as CVE-2019-11707.

The bug Affects Web browsers IonMonkey type confusion with StoreElementHole and FallibleStoreElement, Mozilla said.

IonMonkey is the JavaScript Just-In-Time (JIT) compiler for SpiderMonkey (Mozilla’s JavaScript engine).

It indicates that the attackers attempt to exploit a Type Confusion vulnerability and it can be triggered when incorrect alias information in IonMonkey JIT compiler for setting array elements.

Type confusion vulnerability occurs when a piece of code doesn’t verify the type of object that is passed to it and it could lead to exploit this vulnerability by tricking a user into visiting a malicious web page and execute arbitrary code within the context of the application.

This new Firefox Zero-Day vulnerability affects the browsers Just in Time Compiler and it is currently used for targeted attacks in the wild.

Since the further detailed information was not available at the time, we have reached Qihoo 360 for further information about the exploitation for this Firefox zero-day vulnerability but there is no response at the time of writing.

Mozilla released Firefox 72.0.1 and Firefox ESR 68.4.1. You can download the new Firefox version for all platform here

While this Firefox Zero-Day vulnerability was exploited in targeted attacks, Firefox users are advised to upgrade as soon as possible.

Also Read: Hackers Exploit Android Vulnerability to Install Malware Without User Interaction Via Google Play

Source link

- Advertisement -

More articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest article

Netflix’s Blood of Zeus is no Castlevania, but it should tide you over until season 4

Honestly, I was pretty thrilled when Netflix announced Blood of Zeus. A mature anime miniseries, drawing on Greek mythology, made by the studio behind...

Lenovo Legion Phone Duel, a bizarre new gaming phone, is available to buy now

If you're looking to buy a new gaming phone the Lenovo Legion Phone Duel is out today, and it might be great for the...

Packers vs Texans live stream: how to watch NFL week 7 online from anywhere

The Green Bay Packers roll into week 7 with an impressive 4-1 record and all signs point to that becoming 5-1 after today's game...

Steelers vs Titans live stream: how to watch NFL week 7 online from anywhere

Two of the NFL’s three remaining undefeated teams do battle at Heinz Field today in the pick of week 7's games. After a three-week...

Why a sports watch is a great investment – even if you hate sports

A few days ago, Garmin released its latest feature-packed watch - one designed not for running, boating or driving, but for gaming. The Garmin...