During the hacking competition, two major vulnerabilities in the latest version of Firefox, Firefox 66. This led Mozilla to release a new patch to address the security issues.
Last week, Mozilla released Firefox version 66.0. However, for the past 2-3 days, version 66.0.1 has been available to address two vulnerabilities, CVE-2019-9810 and CVE-2019-9813. The vulnerabilities were disclosed by Richard Zhu, Amat Cama, and Niklas Baumstark.
Mozilla has provided some information about the two vulnerabilities. CVE-2019-9810 allows a buffer overflow attack and causes a bounds checking issue due to incorrect information in JMIT IonMonkey for the Array.prototype.slice method.
The CVE-2019-9813 vulnerability causes an issue in the IonMonkey JIT code, which allows hackers to gain access to memory.
Given the situation, all users should install the updated Firefox 66.0.1, according to Mozilla. The company rated the two vulnerabilities "critical" and recommended that users act quickly.
The update is already available on Windows and macOS platforms via OTA (over-the-air) updates.
Mozilla is on the lookout for other security issues in the new version, but has already begun preparations for the Firefox 67.0 series, which will be available in May.
