Yesterday, the Mozilla team released a new updated version, 67.0.3, of the Firefox browser, as there is a critical vulnerabilitythat hackers are already exploiting.
According to a statement made by Mozilla engineers, this is a “type confusing” vulnerability, which can occur when manipulating JavaScript elements, due to problems in Array.pop.
Mozilla has information that some hackers are already exploiting this vulnerability.
Samuel Groß , a security researcher, along with Google 's Project Zero security team and Coinbase researchers, were the ones who discovered the vulnerability in question, which was named CVE-2019-11707.
At the moment, there is not much information about the zero-day vulnerability and the attacks that have been carried out. All we know is the brief description published on Mozilla's site.
However, if we consider the researchers who discovered the vulnerability, we could assume that hackers exploiting the bug are carrying out attacks on cryptocurrency.
Groß and the other researchers did not provide further information about the vulnerability.
One observation we could make is that zero-day vulnerabilities in Firefox are not a common occurrence. On the contrary, it is rare that such a bug has been discovered in the browser. The last time the Mozilla team was asked to issue a patch to address a zero-day vulnerability was in December 2016. The vulnerability was being used by some to “unmask” Tor Browser users, that is, to prevent them from remaining anonymous.

In contrast, Google recently addressed such a security in its browser. Specifically, the company released a patch in March. The zero-day vulnerability, which was fixed by the patch, was being used in conjunction with another zero-day vulnerability, which was found in Windows 7. Hackers were exploiting both bugs and carrying out attacks.
