Yesterday, Mozilla released a patch for its Firefox browser that addresses the zero-day flaw. According to reports from online sources, the vulnerability was actively exploited by malicious actors, but Mozilla representatives have not commented on this information yet.

It is known that the vulnerability affected the JavaScript JIT compiler IonMonkey for SpiderMonkey, one of the core components of Firefox's engine, which handles JavaScript operations. Experts classified the issue as a type confusion vulnerability, where the data written to memory is first defined as one data type, but later switches to another type due to certain manipulations. By exploiting this vulnerability, attackers could execute arbitrary code remotely on the compromised system.
According to available information, the vulnerability in question was discovered by specialists from the Chinese company Qihoo 360. Company representatives stated that they are aware of several instances where the mentioned vulnerability was used maliciously. It should be noted that recently a tweet from Qihoo 360's account mentioned they had found an actively exploited zero-day vulnerability in Internet Explorer. However, that message was later deleted.
As for the vulnerability in question, it has been fixed in Firefox versions 72.0.1 and Firefox ESR 68.4.1. Mozilla browser users are recommended to update to the latest version to avoid becoming victims of attackers.
Source: 3dnews.ru
