Two zero-day vulnerabilities have been fixed in the Mozilla Firefox browser

Mozilla developers have released new versions of the Firefox web browsers, Firefox 74.0.1 and Firefox ESR 68.6.1. Users are advised to update their browsers, as the new versions fix two zero-day vulnerabilities that are being actively exploited by hackers.

Two zero-day vulnerabilities have been fixed in the Mozilla Firefox browser

The vulnerabilities in question are CVE-2020-6819 and CVE-2020-6820, related to how Firefox manages its memory space. They represent so-called use-after-free vulnerabilities and allow hackers to plant arbitrary code in Firefox's memory for further execution within the browser. Such vulnerabilities can be used for remote code execution on victim devices.

Detailed information about actual attacks using the mentioned vulnerabilities is not disclosed, which is standard practice among software vendors and security researchers. This is because they typically focus on promptly addressing discovered issues and delivering fixes to users before conducting a more thorough investigation of the attacks.

According to available data, Mozilla will investigate attacks using these vulnerabilities in collaboration with the cybersecurity firm JMP Security and researcher Francisco Alonso, who was the first to identify the issue. The researcher suggests that the vulnerabilities fixed in the latest Firefox update may also affect other browsers, although there are currently no known instances of these flaws being exploited by hackers across different web browsers.



Source: 3dnews.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster