Following the releases of Firefox 67.0.3 and 60.7.1 the additional corrective releases 67.0.4 and 60.7.2, which fix the second 0-day (CVE-2019-11708), which allows bypassing the sandbox isolation mechanism. The issue exploits manipulation of the IPC call Prompt:Open to open web content from the child process in the parent process which does not apply the sandbox. In combination with another vulnerability, this issue allows bypassing all layers of protection and executing code on the system.
The vulnerabilities identified in the last two Firefox releases to carry out an attack on the employees of the cryptocurrency exchange Coinbase, and also to spread malware for the macOS platform. , the information about the first vulnerability was reported to Mozilla by a participant of the Google Project Zero on April 15, and on June 10, it was in the beta version of Firefox 68 (likely the attackers analyzed the published fix and prepared an exploit by using another vulnerability to bypass the sandbox isolation).
Source: opennet.ru
