Security Experts:

Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Mozilla Patches Firefox Zero-Day Exploited in Targeted Attacks

Updates released by Mozilla on Wednesday for its Firefox browser address a zero-day vulnerability that has been exploited in targeted attacks.

Updates released by Mozilla on Wednesday for its Firefox browser address a zero-day vulnerability that has been exploited in targeted attacks.

The vulnerability, tracked as CVE-2019-17026 and classified as having critical impact, has been described by Mozilla as an “IonMonkey type confusion with StoreElementHole and FallibleStoreElement.” IonMonkey is the Just-in-Time (JIT) compiler for Firefox’s SpiderMonkey JavaScript engine.

“Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion,” Mozilla explained in its advisory.

Mozilla says it’s aware of targeted attacks exploiting this zero-day, but no other information has been made available.

A Current Activity bulletin released by the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) says the vulnerability could allow an attacker to take control of an affected system.

The flaw has been patched with the release of Firefox 72.0.1 and Firefox ESR 68.4.1, and users have been advised to update their installations.

Mozilla has credited Chinese cybersecurity company Qihoo 360 for informing it about the vulnerability. ZDNet reported that Qihoo 360 posted a tweet saying that the Firefox zero-day had been exploited alongside an Internet Explorer zero-day, but the tweet has been deleted and there is no word from Microsoft regarding an Internet Explorer zero-day.

Mozilla last year patched two Firefox zero-day vulnerabilities that had been exploited to deliver Mac malware to cryptocurrency exchanges.

The organization this week released Firefox 72, which improves privacy by allowing users to delete telemetry data and by blocking fingerprinting scripts by default. Firefox 72 also patches nearly a dozen vulnerabilities, including 5 rated high severity. 

Related: Tech Support Scammers Exploiting Unpatched Firefox Bug

Related: Mac Malware Delivered via Firefox Exploits Analyzed

Related: Firefox Zero-Day Exploited to Deliver Malware to Cryptocurrency Exchanges

Written By

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Expert Insights

Related Content

Malware & Threats

Microsoft plans to improve the protection of Office users by blocking XLL add-ins from the internet.

Mobile & Wireless

Technical details published for an Arm Mali GPU flaw leading to arbitrary kernel code execution and root on Pixel 6.

Cloud Security

VMware vRealize Log Insight vulnerability allows an unauthenticated attacker to take full control of a target system.

Mobile & Wireless

Apple rolled out iOS 16.3 and macOS Ventura 13.2 to cover serious security vulnerabilities.

Mobile & Wireless

Apple’s iOS 12.5.7 update patches CVE-2022-42856, an actively exploited vulnerability, in old iPhones and iPads.

Vulnerabilities

Security researchers have observed an uptick in attacks targeting CVE-2021-35394, an RCE vulnerability in Realtek Jungle SDK.

Vulnerabilities

Google has awarded more than $25,000 to the researchers who reported the vulnerabilities patched with the release of the latest Chrome update.

Mobile & Wireless

Two vulnerabilities in Samsung’s Galaxy Store that could be exploited to install applications or execute JavaScript code by launching a web page.