Active Stocks
Thu Apr 18 2024 15:59:07
  1. Tata Steel share price
  2. 160.00 -0.03%
  1. Power Grid Corporation Of India share price
  2. 280.20 2.13%
  1. NTPC share price
  2. 351.40 -2.19%
  1. Infosys share price
  2. 1,420.55 0.41%
  1. Wipro share price
  2. 444.30 -0.96%
Business News/ Technology / News/  Government has a ‘high severity’ warning for Mozilla Firefox users: Details
BackBack

Government has a ‘high severity’ warning for Mozilla Firefox users: Details

Successful exploitation of the vulnerability could allow a remote attacker to perform arbitrary code execution on the targeted system

A vulnerability in Mozilla Firefox browser could allow a remote attacker to execute arbitrary codesPremium
A vulnerability in Mozilla Firefox browser could allow a remote attacker to execute arbitrary codes

The Indian Computer Emergency Response Team (CERT-In) has issued an advisory for Mozilla Firefox users. Marked as ‘high’ severity rating, the cyber security agency said that a vulnerability in the Mozilla Firefox browser can allow a remote attacker to perform arbitrary code execution on the targeted system.

CERT-In’s advisory states that this vulnerability exists in Mozilla Firefox due to use-after-free error in libaudio when used on Android API below version 30. “A remote attacker can exploit this vulnerability by persuading a victim to visit a specially crafted website," it further states.

Successful exploitation of this vulnerability could allow a remote attacker to perform arbitrary code execution on the targeted system, it adds.

Are all Mozilla Firefox users impacted by the vulnerability?

In its advisory, CERT-In says that Mozilla Firefox versions prior to 110.1.0 are at risk. It also states that the vulnerability exists on the Android version of the browser. Other versions of Firefox are unaffected.

What should the impacted users do?

Mozilla says that it has fixed the above mentioned vulnerability with the version 110.1.0. “A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. This bug only affects Firefox for Android. Other versions of Firefox are unaffected," it says.

The CERT-In advises the affected users to upgrade to Mozilla Firefox version 110.1.0 to stay safe.

In a related news, Mozilla Firefox has received three new extensions for its Android web browser. This will offer users an improved web surfing experience and simplify certain tasks. The extensions received by Mozilla Firefox include hiding the user email address while signing up to the website, removing tracking elements before sharing a URL and listening to an article. Using the ‘Firefox Relay’, users can hide their real email addresses. It will help them to protect their identity and comes across as a better safety feature. This would not let online entities collect your email address and use them for marketing or other prudent purposes.

Unlock a world of Benefits! From insightful newsletters to real-time stock tracking, breaking news and a personalized newsfeed – it's all here, just a click away! Login Now!

Catch all the Technology News and Updates on Live Mint. Download The Mint News App to get Daily Market Updates & Live Business News.
More Less
Published: 15 Mar 2023, 10:33 AM IST
Next Story footLogo
Recommended For You
Switch to the Mint app for fast and personalized news - Get App