Mozilla Firefox 72.0.1 Debuts to Fix an Actively Exploited Zero-Day Vulnerability

The latest zero-day vulnerability has been indexed as CVE-2019-17026.

Advertisement
By Jagmeet Singh | Updated: 9 January 2020 12:26 IST
Highlights
  • Mozilla Firefox 72.0.1 is available for download
  • A security advisory has been issued to detail the flaw
  • Mozilla last year fixed two zero-day vulnerabilities in Firefox

Mozilla has released the new Firefox version just a day after bringing its version 72.0.0

Mozilla has released Firefox 72.0.1 that patches an actively exploited zero-day vulnerability. The flaw, which is the third zero-day that the Firefox maker has fixed over the last year after patching two major security loopholes in June last year, impacted JavaScript JIT compiler IonMonkey. It was first reported by China's Qihoo 360. The new Firefox release comes just a day day after Mozilla brought its version 72.0.0 with fixes for six high-rated vulnerabilities. Three of those loopholes could allow attackers to run malicious code remotely on affected systems to gain backdoor access.

The latest zero-day vulnerability has been indexed as CVE-2019-17026. Mozilla has confirmed through a security advisory that the flaw has been fixed in Firefox 72.0.1 as well as Firefox ESR 68.4.1.

“Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw,” the company noted while describing the vulnerability in its advisory.

Advertisement

Mozilla has credited Qihoo 360 for reporting the flaw. However, further clarity on its impact hasn't been provided.

Advertisement

The vulnerability was categorised as a type confusion, which is potentially a critical error that could impact data processing. It is unclear that how it has been leveraged by attackers, though.

As reported by Catalin Cimpanu of ZDNet, Qihoo 360 Core highlighted that in addition to the flaw existed in Firefox, a zero-day vulnerability is affecting Internet Explorer. The Chinese firm, however, reportedly deleted the details revealing the issue within Microsoft's Web browser after briefing posting them on Twitter.

Advertisement

Mozilla in June last year fixed two zero-day vulnerability issues that impacted Coinbase employees and Mac users involved in cryptocurrency exchange. The vulnerabilities were indexed as CVE-2019-11707 and CVE-2019-11708.

Users are advised to download the latest Firefox version to avoid any security issues. The browser can be updated by going through Help > About Firefox.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement
Popular Mobile Brands
  1. From iPhone 17 to New Apple Watch Models: What to Expect from Apple Event
  2. Samsung Galaxy S25 FE Accessories Leaked Ahead of September 4 Launch
  3. Amazon Great Indian Festival Sale: Deals on Smartphones, Laptops Teased
  4. YouTube Reportedly Cracks Down on Premium Family Plan Sharing
  5. Redmi 15 5G, Note 14 Pro Prices Dropped During Diwali With Xiaomi Sale
  6. A Hidden Mantle "Sandwich" May Be What Really Holds Up the Himalayas
  7. Apple iPhone 17 and iPhone 17 Pro: Expected Features, Specs, and Price
  8. IFA 2025 Begins This Week: All the Announcements We Expect
  9. Apple Rolls Out iOS 26 Beta 9 for iPhone Ahead of iPhone 17 Launch
  10. Oppo A5i Pro 5G Launched With 6,000mAh Battery, 50-Megapixel Camera
  1. Oppo A5i Pro 5G Launched With 6,000mAh Battery, 50-Megapixel Primary Camera: Price, Specifications
  2. Call of Duty Film Adaptation in the Works as Paramount and Activision Announce Deal
  3. Samsung Galaxy S25 FE Accessories Leaked Ahead of Galaxy Unpacked Launch Event on September 4
  4. Apple Rolls Out iOS 26 Beta 9 Update for iPhone With Bug Fixes Ahead of iPhone 17 Launch
  5. BCCI Says Crypto, Real Money Gaming Platforms Can’t Bid for Team India’s Title Sponsorship
  6. Scientists Discover Hidden Mantle Layer Beneath the Himalayas Challenging Century-Old Theory
  7. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  8. Microsoft Testing Native Clipboard Sync Feature to Share Text Between Windows PCs, Android Devices
  9. Su From So OTT Release: When and Where to Watch This Kannada-Language Horror-Comedy Online
  10. Sennheiser Momentum 4 Wireless 80th Anniversary Edition Launched in India With Up to 60 Hour Battery Life
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.