2 new 0-Day bugs in Firefox under active attack, update immediately

Mozilla has released an update to Firefox due to two high-risk security vulnerabilities that it says are currently being actively exploited by criminals.

Firefox

The zero-day errors CVE-2022-26485 and CVE-2022-26486, described as issues affecting the XSLT language, which is based on XML and is used to convert XML documents into web pages or PDF documents, as well as WebGPU which is a new web standard, a successor to the current library WebGL JavaScript.

Mozilla says it has had reports of attacks exploiting the two vulnerabilities, but has not released technical details about the attacks or the of the malicious actors who exploit them.

Qihoo 360 ATA security researchers Wang Gang, Liu Jialei, Du Sihang, Huang Yi and Yang Kang have been credited with discovering and reporting deficiencies.

Considering the active exploitation of these bugs so far, it is recommended to to upgrade as soon as possible in Firefox 97.0.2, Firefox ESR 91.6.1, Firefox for Android 97.3.0, Focus 97.3.0 and . 6.2.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.
Firefox, Mozilla, 0-day, zero-day

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).