In case someone missed this (i did :(, story from a week ago), forks also should be updated by now
Mozilla has revealed that a critical security flaw impacting Firefox and Firefox Extended Support Release (ESR) has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2024-9680 (CVSS score: 9.8), has been described as a use-after-free bug in the Animation timeline component.
The issue has been addressed in the following versions of the web browser -
Firefox 131.0.2
Firefox ESR 128.3.1, and
Firefox ESR 115.16.1.
Supposedly Windows users are safe. Which blows my mind because Windows is usually the least safe.
windows was only the least safe because it had the largest user marketshare, therefore was more effective to target them.
in the age where less people are using pcs and optimg for mobile, it makes more sense to target mobile, especially since its way more likely to have sensitive information than an arbitrary computer would.
Contemporary phones are intentionally portable tracking and data collection and transmission devices, all ignoring and not really asking for the consent of the buyer.
It fucking sucks.
True true
Windows was the largest and it sucked at security. It’s better today but the reputation is still well deserved.
This says 131.0.2 was out on october 9th, which is the day before the article you posted, hopefully we’re all good
https://www.mozilla.org/en-US/firefox/131.0.2/releasenotes/
mine had already updated to 131.0.3
Its mainly reminder for forks, like zen, librewolf etc. Or those who break autoupdate like me
Its good you posted! I was just commenting to add additional info.
mine had already updated to 131.0.3
Yeah I checked mine and it’s updated to the same, I got super scared for a moment.
Has flatpak Firefox been updated yet? Last time I checked it was still (I think) 131.0 but that was a few days ago.
I assume this also affects mobile Firefox like Firefox/Fennec for Android? The version of Fennec on F-Droid is like 2 months old.
- ∞ 🏳️⚧️Edie [it/its, she/her, fae/faer, love/loves, ze/hir, des/pair, none/use name, undecided]@hexbear.netEnglish4·20 days ago
Nope. https://www.mozilla.org/en-US/security/advisories/mfsa2024-45/ < this clearly has “For Android” in it, which https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/ doesn’t.
I haven’t seen mentions of mobile anywhere maybe its sufficiently different?