Firefox is vulnerable too

By
Follow google news

An “extremely critical” flaw has been found in Mozilla’s Firefox browser. According to some reports exploit code is already in the wild.

The exploit works by fooling the browser into thinking a software has arrived from a White-listed site.


"We understand that a change made to Mozilla Update has made the vulnerability effectively unexploitable if you only have update.mozilla.org and addons.mozilla.org in your software installation whitelist (accessible from the Web Features or Content panel in the Options/Preferences window), which is the default setting," said a Mozilla spokesperson on the company's website.

If compromised a hacker could pass malicious Java Script and run arbitrary code on a user's system.

A Firefox update to correct the flaw is expected shortly. In April SC reported Firefox passed 50 million downloads. Many of which are a result of people migrating from Microsoft's Internet Explorer in the understanding Mozilla's browser will have less vulnerabilities. But some security experts have suggested that Firefox's newfound popularity will make it a target for hackers.

Firefox's other rival, the Opera browser, has also been having a good time of late. Last week SC reported two million users had downloaded its version 8.

www.mozillazine.org

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Microsoft can't kill dogged researcher's Copilot for Word worm

Microsoft can't kill dogged researcher's Copilot for Word worm

Russia-linked "Midnight Blizzard" group hijacks hotel wi-fi with CaptiveCrunch

Russia-linked "Midnight Blizzard" group hijacks hotel wi-fi with CaptiveCrunch

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Arch Linux halts package adoptions after malware hijacking wave

Arch Linux halts package adoptions after malware hijacking wave

Log In

  |  Forgot your password?