A corrective release of Firefox 120.0.1 is now available, which includes the following fixes:
- Fixed an issue that was causing slow startup times.
- Resolved a problem that resulted in 100% CPU usage when opening certain websites, including Google Maps.
- Fixed an issue that caused a green screen when trying to watch videos on YouTube if hardware-accelerated video decoding was enabled.
- Addressed issues with the status bar continuing to display while watching videos in full-screen mode.
- Fixed crashes occurring on Linux platforms on some systems with Aarch64 architecture and memory page sizes other than 4KB.
Additionally, there is a corrective release of Chrome 119.0.6045.199 for Windows, Mac, and Linux, which fixes a serious vulnerability (CVE-2023-6345) that is already being exploited by attackers (0-day). This issue is also addressed in release 118.0.5993.159 of the separately supported Extended Stable branch.
Details are not yet disclosed, but it is reported that the 0-day vulnerability is caused by an integer overflow in the Skia 2D library. The new version also addresses: a vulnerability (CVE-2023-6348) caused by improper type handling (Type Confusion) in Spellcheck code, buffer overflow in libavif (CVE-2023-6350), and accesses to already freed memory in Mojo (CVE-2023-6347), WebAudio (CVE-2023-6346), and libavif (CVE-2023-6351).
Source: opennet.ru
