Firefox 97 Is Under Attack, Update Now to Protect Yourself

Firefox Logo Hero Image 675px

Mozilla has updated Firefox to version 97.0.2 to fix two active vulnerabilities currently being exploited in the wild. If you’re a Firefox user, you’re going to want to update as soon as possible to make sure your browser is secure.

The exploits are CVE-2022-26485 and CVE-2022-26486. Mozilla described the exploits on its website. “Removing an XSLT parameter during processing could have led to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw,” is how the company describes CVE-2022-26485.

For CVE-2022-26486, the company said, “An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw.”

Advertisement

Mozilla credits finding the exploits to researchers at Chinese security firm Qihoo 360 ATA, Wang Gang, Liu Jialei, Du Sihang, Huang Yi, and Yang Kang.

In addition to Firefox 97.0.2, the company has updated Firefox ESR to 91.6.1, Firefox for Android to 97.3.0, and Focus to 97.3.0.

Mozilla lists these as high-impact vulnerabilities, so you definitely don’t want to wait to update Firefox. Anytime a significant vulnerability is actively being exploited, you want to get the fix as quickly as possible to keep yourself safe and secure while you browse the web.

  • Related Posts

    AI can now generate entire songs on demand. What this means for music as we know it

    Written by Oliver Bown, UNSW Sydney In March, we saw the launch of a “ChatGPT for music” called Suno, which uses generative AI to produce realistic songs on demand from…

    Newly discovered subatomic particle may be the universe’s mythical ‘glueball’

    BEIJING — In the fascinating realm of particle physics, scientists are constantly on the hunt for new subatomic particles that can shed light on the fundamental building blocks of our…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    AI can now generate entire songs on demand. What this means for music as we know it

    • 81 views
    AI can now generate entire songs on demand. What this means for music as we know it

    Newly discovered subatomic particle may be the universe’s mythical ‘glueball’

    • 55 views
    Newly discovered subatomic particle may be the universe’s mythical ‘glueball’

    Deceitful tactics by artificial intelligence exposed: ‘Meta’s AI a master of deception’ in strategy game

    • 76 views
    Deceitful tactics by artificial intelligence exposed: ‘Meta’s AI a master of deception’ in strategy game

    Caterbot or Robatapillar? Scientists create bug-like robot using origami

    • 73 views
    Caterbot or Robatapillar? Scientists create bug-like robot using origami

    Mysteries of the Carrington Event, the largest solar superstorm in modern times, unraveled by tree rings

    • 54 views
    Mysteries of the Carrington Event, the largest solar superstorm in modern times, unraveled by tree rings

    New ‘atomic glue’ could pave way for powerful new quantum devices

    • 41 views
    New ‘atomic glue’ could pave way for powerful new quantum devices