Critical Firefox Vuln Used in Targeted Attacks

  /     /     /  
Publicated : 23/11/2024   Category : security


Critical Firefox Vuln Used in Targeted Attacks


Mozilla has released patches for the bug reported by Coinbase.



Mozilla has patched a critical vulnerability under active exploit in the Firefox browser. 
Digital currency exchange Coinbase reported the vulnerability to Mozilla after discovering it in use for targeted attacks. According to the Mozilla advisory, the type confusion vulnerability (
CVE-2019-11707
) can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. 
The researcher who discovered the flaw – Samuel Groß of Google Project Zero and Coinbase Security – 
stated on Twitter
: The bug can be exploited for RCE but would then need a separate sandbox escape. However, most likely it can also be exploited for UXSS which might be enough depending on the attackers goals.
The vulnerability has been fixed in Firefox 67.0.3 and Firefox ESR 60.7.1. Read more 
here
and
here
.

Last News

▸ ArcSight prepares for future at user conference post HP acquisition. ◂
Discovered: 07/01/2025
Category: security

▸ Samsung Epic 4G: First To Use Media Hub ◂
Discovered: 07/01/2025
Category: security

▸ Many third-party software fails security tests ◂
Discovered: 07/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Critical Firefox Vuln Used in Targeted Attacks