Latest in Firefox

Image credit:

Firefox has a new security hole, but you can already patch it

Steve Dent, @stevetdent
August 7, 2015
Share
Tweet
Share

Sponsored Links

Yesterday, someone noticed that an ad from a Russian news site was exploiting a serious vulnerability in the Firefox browser. According to a Mozilla security post, the attacker was able to bypass the browser's "origin policy" (its front line of security), inject a malicious javascript script and download sensitive local files to a server in the Ukraine. Mozilla said the attack was "surprisingly developer-focused for an exploit launched a general audience news site," because it hunted browser and FTP configuration files. It added that the "exploit leaves no trace that it has run on the local machine."

The organization said the malicious scripts can affect PC and Linux computers, but not Macs. Apple users are still advised to update, though, as hackers could develop a different attack script for OS X. Luckily, the person who spotted the flaw was security researcher Cody Crews, who immediately notified Mozilla. It has patched the flaw with Firefox version 39.0.3, so now would be a good time to get it.

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.
Comment
Comments
Share
Tweet
Share

Popular on Engadget

The 2020 Engadget Holiday Gift Guide

The 2020 Engadget Holiday Gift Guide

View
Scientists might know why astronauts develop health problems in space

Scientists might know why astronauts develop health problems in space

View
Belkin’s new wireless charger tries to do what AirPower promised

Belkin’s new wireless charger tries to do what AirPower promised

View
The best Black Friday tech deals we could find

The best Black Friday tech deals we could find

View
'Spider-Man: Miles Morales' bug gives NYC the patio heater superhero it needs

'Spider-Man: Miles Morales' bug gives NYC the patio heater superhero it needs

View

From around the web

Page 1Page 1ear iconeye iconFill 23text filevr