• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
mozilla rushes to patch webp critical zero day exploit in firefox

Mozilla Rushes to Patch WebP Critical Zero-Day Exploit in Firefox and Thunderbird

You are here: Home / General Cyber Security News / Mozilla Rushes to Patch WebP Critical Zero-Day Exploit in Firefox and Thunderbird
September 13, 2023

Mozilla on Tuesday launched security updates to solve a critical zero-day vulnerability in Firefox and Thunderbird that has been actively exploited in the wild, a working day following Google released a deal with for the issue in its Chrome browser.

The shortcoming, assigned the identifier CVE-2023-4863, is a heap buffer overflow flaw in the WebP impression format that could outcome in arbitrary code execution when processing a specifically crafted impression.

“Opening a malicious WebP graphic could direct to a heap buffer overflow in the information procedure,” Mozilla claimed in an advisory. “We are aware of this issue getting exploited in other solutions in the wild.”

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


In accordance to the description on the National Vulnerability Databases (NVD), the flaw could let a distant attacker to execute an out-of-bounds memory write via a crafted HTML web page.

Apple Security Engineering and Architecture (SEAR) and the Citizen Lab at The College of Toronto’s Munk Faculty have been credited with reporting the security issue. It has been dealt with in Firefox 117..1, Firefox ESR 115.2.1, Firefox ESR 102.15.1, Thunderbird 102.15.1, and Thunderbird 115.2.2.

Impending WEBINARWay Far too Susceptible: Uncovering the Point out of the Identity Attack Surface

Accomplished MFA? PAM? Assistance account safety? Come across out how well-outfitted your business really is from identity threats

Supercharge Your Expertise

The growth arrives a day after Google unveiled fixes for the exact same flaw in Chrome, noting it’s “knowledgeable that an exploit for CVE-2023-4863 exists in the wild.”

Previous 7 days, Apple also unveiled patches to plug two actively exploited security holes that the Citizen Lab said have been weaponized as part of a zero-click on iMessage exploit chain named BLASTPASS to deploy the Pegasus adware on totally-patched iPhones running iOS 16.6.

Whilst unique aspects relating to the flaws’ exploitation continue being not known, it’s suspected that they are all being leveraged to focus on people who are at an elevated risk, this sort of as activists, dissidents, and journalists.

Found this short article exciting? Comply with us on Twitter  and LinkedIn to browse additional distinctive information we put up.


Some pieces of this report are sourced from:
thehackernews.com

Previous Post: «critical github vulnerability exposes 4,000+ repositories to repojacking attack Critical GitHub Vulnerability Exposes 4,000+ Repositories to Repojacking Attack
Next Post: Update Adobe Acrobat and Reader to Patch Actively Exploited Vulnerability update adobe acrobat and reader to patch actively exploited vulnerability»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.