Mozilla has released security updates for both Firefox and Thunderbird to address 15 vulnerabilities, with five of them rated as "high severity." Among the high-severity flaws, one involves an out-of-bounds write in the ANGLE (Almost Native Graphics Layer Engine), an open-source graphics engine used in Firefox and Chrome for WebGL. Tracked as CVE-2024-0741, this flaw could potentially lead to a denial of service or arbitrary code execution by corrupting memory. Another high-severity issue (CVE-2024-0742) is described as a "failure to update user input timestamp," allowing unintended activation or dismissal of certain browser prompts and dialogs. Mozilla also addressed CVE-2024-0743, an unchecked return value in TLS handshake code; CVE-2024-0744, a JavaScript code bug with a dereferenced wild pointer value; and CVE-2024-0745, a stack buffer overflow in WebAudio. Additionally, a medium-severity bug was patched, preventing an attacker from setting an arbitrary URI in the address bar or history. Mozilla fixed another medium-severity issue where a phishing site could repurpose an about: dialog to display phishing content with an incorrect origin in the address bar. The remaining vulnerabilities, also medium-severity, could lead to crashes, Content Security Policy bypass, permissions request bypass, privilege escalation, or HSTS policy bypass. Firefox 122, released on January 23, addresses these security flaws, while Thunderbird 115.7 and Firefox ESR 115.7 include patches for nine of the vulnerabilities. Mozilla did not report any active exploitation of these vulnerabilities in the wild.
A new self-propagating malware strain dubbed GlassWorm has been discovered infecting Visual Studio Code (VS Code) extensions distributed via both Microsoft’s official Marketplace...
SquareX disclosed a new class of attacks called AI Sidebar Spoofing, where malicious browser extensions render pixel-perfect replicas of trusted AI sidebars (Comet and consumer bro...
A recent update to HP’s OneAgent software has caused a major outage across enterprise environments, disconnecting Windows 11 devices from Microsoft Entra ID. Version 1.2.50.9581,...