Cyber Security

Firefox Patches Multiple High Severity Vulnerabilities

Mozilla has released Firefox 129, addressing multiple high-severity vulnerabilities. These patches are critical for enhancing the browser’s security and protecting users from potential exploits.

Detailed Vulnerability Table

The latest Firefox update patches several critical vulnerabilities, each significantly impacting user security. Below is a summary of the most notable issues:

How to Build a Security Framework With Limited Resources IT Security Team (PDF) - Free Guide

CVE IDImpactDescriptionReferences
CVE-2024-7518HighOut-of-bounds memory access in graphics shared memory handling.Bug 1875354
CVE-2024-7519HighOut of bounds memory access in graphics shared memory handling.Bug 1902307
CVE-2024-7520The fullscreen notification dialog can be obscured by document content.Type confusion in WebAssembly.Bug 1903041
CVE-2024-7521HighIncomplete WebAssembly exception handling.Bug 1904644
CVE-2024-7522HighOut of bounds read in editor component.Bug 1906727
CVE-2024-7523HighDocument content could partially obscure security prompts (affects Android versions).Bug 1908344
CVE-2024-7524HighCSP strict-dynamic bypass using web-compatibility shims.Bug 1909241
CVE-2024-7525HighMissing permission check when creating a StreamFilter.Bug 1909298
CVE-2024-7526HighUninitialized memory used by WebGL.Bug 1910306
CVE-2024-7527HighUse-after-free in JavaScript garbage collection.Bug 1871303
CVE-2024-7528HighUse-after-free in IndexedDB.Bug 1895951
CVE-2024-7529ModerateDocument content could partially obscure security prompts.Bug 1903187
CVE-2024-7530ModerateUse-after-free in JavaScript code coverage collection.Bug 1904011
CVE-2024-7531LowPK11_Encrypt using CKM_CHACHA20 can reveal plaintext on Intel Sandy Bridge machines.Bug 1910306

The vulnerabilities addressed in this update pose significant risks, including potential spoofing attacks, memory corruption, sandbox escapes, and unauthorized data access.

For instance, CVE-2024-7518 could allow a malicious site to obscure fullscreen notification dialogs, potentially tricking users into performing unintended actions.

Similarly, CVE-2024-7519 involves out-of-bounds memory access, which could lead to memory corruption and sandbox escapes. Given the high impact of these vulnerabilities, users are strongly advised to update their Firefox browsers to version 129 immediately.

This update enhances security and ensures a safer browsing experience by mitigating the risks associated with these vulnerabilities.

Mozilla’s proactive approach to addressing these issues underscores the importance of regular software updates and vigilance in cybersecurity practices. Users should remain informed about such updates and apply them promptly to protect their data and privacy.

Are you from SOC and DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Free Access

Dhivya

Divya is a Senior Journalist at Cyber Security news covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago