Firefox Vulnerability Lets Attackers Steal Information; Mozilla Issues Patch

Advertisement
By Manish Singh | Updated: 7 August 2015 20:20 IST

Mozilla is warning users about a vulnerability in its Firefox Web browser that could allow attackers to steal information from their computer. The browser-maker urges users to update Firefox to the latest available version -- v39.0.3 or above - to protect their system from the said vulnerability.

While by default Firefox automatically updates itself, those who have the setting off will have to manually update via the 'About Firefox' setting in the Help tab. Earlier this week, the company was notified by security researcher Cody Crews about a malicious ad on a Russian news portal that was exploiting a vulnerability in Firefox's PDF Viewer, a built-in feature. The exploit seeks sensitive files on the victim's computer and uploads it to a suspicious server reportedly located in Ukraine.

Versions of Firefox that don't support PDF Viewer including Firefox for Android client aren't vulnerable to the exploit. Firefox's Mac client is also not affected. "The vulnerability comes from the interaction of the mechanism that enforces JavaScript context separation (the 'same origin policy') and Firefox's PDF Viewer," wrote Mozilla security chief Daniel Veditz.

Advertisement

"The vulnerability does not enable the execution of arbitrary code but the exploit was able to inject a JavaScript payload into the local file context. This allowed it to search for and upload potentially sensitive local files."

Advertisement

In the blog post, Veditz also notes that the exploit looks for subversion, s3browser, Firezilla, and libpurple configuration files on the Windows systems. On Linux, the payload checks global configuration files in the /etc directory. It also looks into .bashhistory, .mysqlhistory, .pgsql_history, and .ssh configuration files and keys.

Veditz says that people who use ad-blocking tools might not be affected with the vulnerability either, though it isn't too sure about that. Regardless, you would want to update your Firefox Web browser to the latest version.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases This Week: Gandhi Talks, Subedaar, War Machine, Hello Bachhon, and More
  2. OpenAI's GPT-5.4 AI Model Is Here, and It Can Use Your Computer
  3. Here's When the Poco C85x 5G Will be Launched in India
  4. WhatsApp Now Lets You Discover Stickers While Typing Emoji
  5. Vivo X300 Ultra's Telephoto Camera Confirmed to Offer CIPA 7.0 Stabilisation
  6. Google Pixel 10a With 5,100mAh Battery Goes on Sale in India: See Offers
  7. Motorola Edge 70 Fusion Launched in India With 50-Megapixel Sony LYT-710 Camera
  8. OnePlus 15T Key Specifications Confirmed Ahead of Launch in China
  1. Vivo X300 Max With Zeiss Cameras and Android 16 Spotted at MWC 2026, Could Launch Soon
  2. WhatsApp Update Introduces Support for Discovering Stickers While Typing Emoji: How It Works
  3. This AI-Powered Portable Device Claims to Detect Microphones and Jam Audio Recordings
  4. Poco X8 Pro Series Global Launch Date Leaked Ahead of Anticipated Debut: Expected Price, Specifications
  5. MacBook Neo Geekbench Scores Indicate It Performs on Par With iPhone 16 Pro Max
  6. Xiaomi Testing Experimental AI Agent Miclaw, Can Perform Complex Tasks Across Devices
  7. Dear Radhi OTT Release: Where to Watch the Tamil Thriller Online?
  8. With Love Now Streaming on Netflix: Know Everything About Plot, Cast, and More
  9. Kaattaan OTT Release Date Confirmed: When and Where to Watch Vijay Sethupathi Starrer Online?
  10. OnePlus 15T Display Size, Ultrasonic Fingerprint Sensor Confirmed; Geekbench Listing Hints at Chip, Memory
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.