Mozilla Firefox Fixes Zero-Day Exploits That Impacted Coinbase Employees, Mac Users Involved in Cryptocurrency Exchange

Mozilla has listed the vulnerabilities as CVE-2019-11707 and CVE-2019-11708.

Advertisement
By Jagmeet Singh | Updated: 21 June 2019 19:16 IST
Highlights
  • Mozilla released Firefox 67.0.3 to fix the remote code execution bug
  • The bug enabled attackers to run malicious code within Firefox
  • Mozilla brought Firefox 67.0.4 to match the sandbox escape issue

Firefox was impacting Coinbase employees through remote code execution and sandbox escape flaws

Mozilla has patched a couple of zero-day vulnerabilities on Firefox through two separate security updates. While the first zero-day flaw was described as a "remote code execution" vulnerability that enabled remote attackers to run a malicious code within the native process of the Firefox browser, the second one was known as a "sandbox escape" that allowed hackers to execute arbitrary code on the operating system by escaping from Firefox' security sandbox. Some anonymous attackers used the two Firefox security loopholes to plan an attack against Coinbase employees. The issue was confirmed by Coinbase Chief Information Security Officer (CISO) Philip Martin. Separately, one of the patched zero-day vulnerabilities has been found to give backdoor access to Mac machines used for a cryptocurrency exchange.

The remote code execution bug listed as CVE-2019-11707 was first reported by a Google Project Zero researcher. It was patched earlier this week, just before fixing the sandbox escape issue that has been described as CVE-2019-11708. Both flaws notably enabled the attackers to impact the Coinbase staff, which was noted by ZDNet.

"On Monday, Coinbase detected and blocked an attempt by an attacker to leverage the reported zero-day along with a separate zero-day Firefox sandbox escape, to target Coinbase employees," said Coinbase CISO Martin on Twitter. "We walked back the entire attack, recovered, and reported the zero-day to Firefox, pulled apart the malware and infra[structure] used in the attack and are working with various orgs to continue burning down [the] attacker infrastructure and digging into the attacker involved."

Advertisement

Martin added that the attack didn't target customers, though it was aimed at other cryptocurrency organisations as well that were notified.

Advertisement

"We're also releasing a set of IOCs (indicators of compromise) that orgs can use to evaluate their potential exposure," he continued.

The indicators of compromise shared by Martin suggests that attackers would send a spear-phishing email to influence the recipients to visit a webpage that can run a collect personal data stored on Firefox. The attack was notably designed for both Mac and Windows users.

Advertisement

Mozilla brought the Firefox 67.0.3 and Firefox ESR 60.7.1 to fix the initial zero-day bug. Later, it released the Firefox 67.0.4 and Firefox ESR 60.7.2 to patch the second zero-day vulnerability that was associated with the sandbox escape issue and contributed to the Coinbase exploit.

In other news, the remote code execution bug in Firefox that has been listed as CVE-2019-11707 is found to enabled attackers to install a Mac malware. The malware can be installed particularly on machines where a cryptocurrency exchange took place "until fairly recently," macOS security researcher Patrick Wardle pointed out in his blog.

Advertisement

As explained by Ars Technica, the overrides Apple's default security measures, including XProtect and Gatekeeper, to install malicious content on Mac machines through Firefox.

"I do not have direct evidence [Windows users] were targeted as a result of this exploit," independent reverse engineer Vitali Kremez told Ars Technica.

That being said, Windows and Mac both users are highly recommended to install the updated Firefox browser on their computers to avoid uncertain instances.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Mozilla Firefox, Firefox, Mozilla
Advertisement

Related Stories

Popular Mobile Brands
  1. iQOO Neo 11 With Snapdragon 8 Elite SoC Launched: Price, Specifications
  2. Top OTT Releases of the Week: Kantara Chapter 1, Lokah Chapter 1, Idli Kadai, and More
  3. Gemini 3 AI Model Will Be Released Soon, Says Google CEO Sundar Pichai
  4. Realme GT 8 Pro Will Launch in India in November With This Chipset
  5. Vivo X300 Series Launching Today: Everything You Need to Know
  6. Reliance Offers Free 18-Month Google AI Pro with Gemini, Veo to Jio Users
  7. How to Claim 18 Months of Free Google AI Pro Access on the MyJio App
  8. Samsung Galaxy S26 Series Teased to Launch With These Notable Upgrades
  9. Snapdragon 8 Gen 5 Chipset Key Specs, Benchmarks Leak
  10. Vivo S50 Pro Mini Key Specifications Tipped Ahead of Launch
  1. Vivo X300 Series Launched Globally With 200-Megapixel Zeiss Camera, Up to 6.78-Inch Display: Price, Features
  2. Canva Introduces Revamped Video Editor, New AI Tools and a Marketing Platform
  3. Bitchat Becomes Jamaica’s Go-to App as Hurricane Melissa Cripples Communication
  4. Google Maps Is Reportedly Developing a New Power Saving Mode for Navigation
  5. Take-Two CEO Says AI Won't Be 'Very Good' at Making a Game Like Grand Theft Auto
  6. Reliance Users to Get Free Google AI Pro Access for 18 Months Worth Rs. 35,100 With Gemini, Veo Features
  7. Meta’s VR Headsets and AI Glasses Cost the Company $4.4 Billion in Q3 2025
  8. iQOO Neo 11 With 7,500mAh Battery, Snapdragon 8 Elite Chip Launched: Price, Specifications
  9. Telegram Founder Pavel Durov Launches Cocoon, a Decentralised AI Project on TON
  10. Hedda (2025) Now Available for Streaming on Amazon Prime Video: What You Need to Know
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.