2 New Mozilla Firefox 0-Day Bugs Under Active Attack — Patch Your Browser ASAP!
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-26486 +1 in the same advisory: …26485 | Use-After-Free Sandbox Escape in Mozilla Firefox and Thunderbird CVE-2022-26486 is a use-after-free (CWE-416) in the WebGPU inter-process communication (IPC) framework of Mozilla Firefox, triggered when the IPC framework receives an unexpected message. An attacker who can get the browser to process malicious content gains a sandbox escape from the compromised content process, and the flaw was chained with the sibling zero-day CVE-2022-26485 in attacks observed in the wild. Users of Firefox, Firefox ESR, Firefox for Android, Firefox Focus, and Thunderbird running builds prior to the patched releases are affected. Exploitation is confirmed in the wild: the issue was disclosed as a zero-day, added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-07, and CISA urged defenders to patch promptly. Mozilla rated the fix urgent, and the flaw carries a critical CVSS 3.1 score of 9.6 with an EPSS 30-day exploitation probability of about 2.3%. Do: Upgrade immediately: Firefox to 97.0.2 or later, Firefox ESR to 91.6.1 or later, Firefox for Android and Firefox Focus to 97.3.0 or later, and Thunderbird to 91.6.2 or later. Prioritize this patch because the flaw is a confirmed zero-day in CISA KEV; inventory managed endpoints for outdated Firefox/Thunderbird builds and, as an interim mitigation, consider disabling or restricting WebGPU where feasible until updates are applied. | 9.6 group max | 2% | KEV PoC ×2 |
| massplausibly hundreds of millions of users (Firefox alone has roughly 200M+ active users worldwide, plus Firefox for Android and Thunderbird installs) |
Full article374 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMar 07, 2022
Mozilla has pushed out-of-band software updates to its Firefox web browser to contain two high-impact security vulnerabilities, both of which it says are being actively exploited in the wild.
Tracked as CVE-2022-26485 and CVE-2022-26486, the zero-day flaws have been described as use-after-free issues impacting the Extensible Stylesheet Language Transformations (XSLT) parameter processing and the WebGPU inter-process communication (IPC) Framework.
XSLT is an XML-based language used for the conversion of XML documents into web pages or PDF documents, whereas WebGPU is an emerging web standard that's been billed as a successor to the current WebGL JavaScript graphics library.
The description of the two flaws is below –
- CVE-2022-26485 – Removing an XSLT parameter during processing could lead to an exploitable use-after-free
- CVE-2022-26486 – An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape
Use-after-free bugs – which could be exploited to corrupt valid data and execute arbitrary code on compromised systems – stem mainly from a "confusion over which part of the program is responsible for freeing the memory."
Mozilla acknowledged that "We have had reports of attacks in the wild" weaponizing the two vulnerabilities but did not share any technical specifics related to the intrusions or the identities of the malicious actors exploiting them.
Security researchers Wang Gang, Liu Jialei, Du Sihang, Huang Yi, and Yang Kang of Qihoo 360 ATA have been credited with discovering and reporting the shortcomings.
While targeted attacks leveraging zero-days in Firefox have been a relatively rare occurrence when compared to Apple Safari and Google Chrome, Mozilla previously addressed three actively exploited flaws in 2020 and one in 2019.
In light of active exploitation of the flaws, users are recommended to upgrade as soon as possible to Firefox 97.0.2, Firefox ESR 91.6.1, Firefox for Android 97.3.0, Focus 97.3.0, and Thunderbird 91.6.2.
Update: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added the two Firefox zero-day vulnerabilities, along with nine other bugs, to its Known Exploited Vulnerabilities Catalog, requiring federal agencies to apply the fixes by March 21, 2022.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/03/2-new-mozilla-firefox-0-day-bugs-under.html