• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
mozilla rushes to patch webp critical zero day exploit in firefox

Mozilla Rushes to Patch WebP Critical Zero-Day Exploit in Firefox and Thunderbird

You are here: Home / General Cyber Security News / Mozilla Rushes to Patch WebP Critical Zero-Day Exploit in Firefox and Thunderbird
September 13, 2023

Mozilla on Tuesday launched security updates to solve a critical zero-day vulnerability in Firefox and Thunderbird that has been actively exploited in the wild, a working day following Google released a deal with for the issue in its Chrome browser.

The shortcoming, assigned the identifier CVE-2023-4863, is a heap buffer overflow flaw in the WebP impression format that could outcome in arbitrary code execution when processing a specifically crafted impression.

“Opening a malicious WebP graphic could direct to a heap buffer overflow in the information procedure,” Mozilla claimed in an advisory. “We are aware of this issue getting exploited in other solutions in the wild.”

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


In accordance to the description on the National Vulnerability Databases (NVD), the flaw could let a distant attacker to execute an out-of-bounds memory write via a crafted HTML web page.

Apple Security Engineering and Architecture (SEAR) and the Citizen Lab at The College of Toronto’s Munk Faculty have been credited with reporting the security issue. It has been dealt with in Firefox 117..1, Firefox ESR 115.2.1, Firefox ESR 102.15.1, Thunderbird 102.15.1, and Thunderbird 115.2.2.

Impending WEBINARWay Far too Susceptible: Uncovering the Point out of the Identity Attack Surface

Accomplished MFA? PAM? Assistance account safety? Come across out how well-outfitted your business really is from identity threats

Supercharge Your Expertise

The growth arrives a day after Google unveiled fixes for the exact same flaw in Chrome, noting it’s “knowledgeable that an exploit for CVE-2023-4863 exists in the wild.”

Previous 7 days, Apple also unveiled patches to plug two actively exploited security holes that the Citizen Lab said have been weaponized as part of a zero-click on iMessage exploit chain named BLASTPASS to deploy the Pegasus adware on totally-patched iPhones running iOS 16.6.

Whilst unique aspects relating to the flaws’ exploitation continue being not known, it’s suspected that they are all being leveraged to focus on people who are at an elevated risk, this sort of as activists, dissidents, and journalists.

Found this short article exciting? Comply with us on Twitter  and LinkedIn to browse additional distinctive information we put up.


Some pieces of this report are sourced from:
thehackernews.com

Previous Post: «critical github vulnerability exposes 4,000+ repositories to repojacking attack Critical GitHub Vulnerability Exposes 4,000+ Repositories to Repojacking Attack
Next Post: Update Adobe Acrobat and Reader to Patch Actively Exploited Vulnerability update adobe acrobat and reader to patch actively exploited vulnerability»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • BREAKING: 7,000-Device Proxy Botnet Using IoT, EoL Systems Dismantled in U.S. – Dutch Operation
  • OtterCookie v4 Adds VM Detection and Chrome, MetaMask Credential Theft Capabilities
  • Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials
  • Deploying AI Agents? Learn to Secure Them Before Hackers Strike Your Business
  • Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials
  • Beyond Vulnerability Management – Can You CVE What I CVE?
  • Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android
  • Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell
  • 38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases
  • SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root

Copyright © TheCyberSecurity.News, All Rights Reserved.