Potent Firefox 0-day used to install undetected backdoors on Macs

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12+Q7-VS1SPmFBPnHgx9T42F4mXWtNfFvt2-XnBWeBu+NQ@mail.gmail.com>
'Hackers exploited a pair of potent zero-day vulnerabilities in
Firefox to infect Mac users with a largely undetected backdoor,
according to accounts pieced together from multiple people.

Mozilla released an update on Tuesday that fixed a code-execution
vulnerability in a JavaScript programming method known as Array.pop.
On Thursday, Mozilla issued a second patch fixing a
privilege-escalation flaw that allowed code to break out of a security
sandbox that Firefox uses to prevent untrusted content from
interacting with sensitive parts of a computer operating system.
Interestingly, a researcher at Google's Project Zero had privately
reported the code-execution flaw to Mozilla in mid April.

On Monday, as Mozilla was readying a fix for the array.pop flaw,
unknown hackers deployed an attack that combined working exploits for
both vulnerabilities. The hackers then used the attack against
employees of Coinbase, according to Philip Martin, chief information
security officer for the digital currency exchange.'

-- source: https://arstechnica.com/information-technology/2019/06/potent-firefox-0day-used-to-install-undetected-backdoors-on-macs/

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.