Mozilla Firefox 72.0.1 Debuts to Fix an Actively Exploited Zero-Day Vulnerability

The latest zero-day vulnerability has been indexed as CVE-2019-17026.

Advertisement
By Jagmeet Singh | Updated: 9 January 2020 12:26 IST
Highlights
  • Mozilla Firefox 72.0.1 is available for download
  • A security advisory has been issued to detail the flaw
  • Mozilla last year fixed two zero-day vulnerabilities in Firefox

Mozilla has released the new Firefox version just a day after bringing its version 72.0.0

Mozilla has released Firefox 72.0.1 that patches an actively exploited zero-day vulnerability. The flaw, which is the third zero-day that the Firefox maker has fixed over the last year after patching two major security loopholes in June last year, impacted JavaScript JIT compiler IonMonkey. It was first reported by China's Qihoo 360. The new Firefox release comes just a day day after Mozilla brought its version 72.0.0 with fixes for six high-rated vulnerabilities. Three of those loopholes could allow attackers to run malicious code remotely on affected systems to gain backdoor access.

The latest zero-day vulnerability has been indexed as CVE-2019-17026. Mozilla has confirmed through a security advisory that the flaw has been fixed in Firefox 72.0.1 as well as Firefox ESR 68.4.1.

“Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw,” the company noted while describing the vulnerability in its advisory.

Advertisement

Mozilla has credited Qihoo 360 for reporting the flaw. However, further clarity on its impact hasn't been provided.

Advertisement

The vulnerability was categorised as a type confusion, which is potentially a critical error that could impact data processing. It is unclear that how it has been leveraged by attackers, though.

As reported by Catalin Cimpanu of ZDNet, Qihoo 360 Core highlighted that in addition to the flaw existed in Firefox, a zero-day vulnerability is affecting Internet Explorer. The Chinese firm, however, reportedly deleted the details revealing the issue within Microsoft's Web browser after briefing posting them on Twitter.

Advertisement

Mozilla in June last year fixed two zero-day vulnerability issues that impacted Coinbase employees and Mac users involved in cryptocurrency exchange. The vulnerabilities were indexed as CVE-2019-11707 and CVE-2019-11708.

Users are advised to download the latest Firefox version to avoid any security issues. The browser can be updated by going through Help > About Firefox.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Realme P4 Power 5G With 10,001mAh Battery Arrives in India: See Price
  2. Daredevil: Born Again Season 2 OTT Release Date Confirmed: When and Where to Watch it Onli
  3. Redmi Note 15 Pro Series 5G Launched in India With These Features
  4. Sarvam Maya OTT Release Date: When and Where to Watch it Online?
  5. CERN Experiments Confirm Early Universe Behaved Like a Near-Perfect Fluid
  6. iQOO 15R Dark Knight Colourway Teased Weeks Ahead of Launch in India
  7. Moto G67, Moto G77 Debut With 5,200mAh Battery, 32-Megapixel Selfie Camera
  8. Adobe Express Premium Is Now Free for One Year for All Airtel Users
  9. Tecno Camon 50 Pro, Camon 50 Surface on Google Play Console Ahead of Debut
  10. Redmi Buds 8 Pro Launched With ANC, Hi-Res Audio at This Price
  1. Apple Reaches 2.5 Billion Active Devices Worldwide as India Becomes a Key Growth Market
  2. CERN Experiments Confirm Early Universe Behaved Like a Near-Perfect Fluid
  3. NASA’s TESS Captures First Images of Rare Interstellar Comet 3I/ATLAS
  4. Daredevil: Born Again Season 2 OTT Release Date Confirmed: When and Where to Watch it Online?
  5. The Wrecking Crew Starring Jason Momoa and Dave Bautista Now Streaming: What You Need to Know
  6. Redmi Buds 8 Pro Launched With ANC, Hi-Res Audio and Up to 36 Hours of Total Battery Life
  7. Samsung Galaxy Tab S12+ Surfaces on IMEI Database, Could Launch Soon
  8. Champion OTT Release: Where To Watch Roshan Meka’s Telugu Sports Drama Online?
  9. Nothing Won't Launch a Flagship Model in 2026; Company to Focus on Nothing Phone 4a and Audio Products, Carl Pei Says
  10. Redmi Turbo 5 Max Launched With 9,000mAh Battery, Redmi Turbo 5 Tags Along: Price, Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.