Emergency security releases for Firefox have been published and , which address (CVE-2019-17026), which allows for code execution when opening specially crafted pages. The danger is compounded by the fact that even before the fix was made there have been confirmed instances of attacks exploiting this vulnerability, and a working exploit is in the hands of malicious actors. All Firefox users are strongly advised to update their browser urgently, while Tor Browser users need to version 9.0.4, which will be published within a few hours.
Signs of attacks exploiting the 0-day vulnerability were discovered by Chinese antivirus software producers . The issue is caused by incorrect type definition of array elements during operations in object code compiled by the JIT engine IonMonkey. Details are still , but the .
Source: opennet.ru
