Mozilla released a new version of Firefox that fixes an actively exploited zero‑day that could allow attackers to take control of users' computers.
In an advisory, Mozilla rated the vulnerability critical and said it was “aware of targeted attacks in the wild that exploited this flaw.” The company said one or more exploits had been “identified” and warned that the attacks could be leveraged to “take control of an affected system.” Mozilla advisory researchers spoke to researchers at China, who reported the flaw. No other details about the attacks were available.

CVE-2019-17026, is a 'Type Confusion', a potentially critical bug that can lead to data being written to or read from memory locations that are normally out of bounds. These out-of-bounds reads allow attackers to locate memory locations where malicious code is stored, so they can bypass protections such as random space structure. Out-of-bounds reads can also cause damage.
The flaw was fixed in Tuesday's release of Firefox 72.0.1. The patch came a day after version 72 had 11 other vulnerabilities, six of which were highly rated. Three of those six bugs could allow attackers to execute malicious code on affected computers.
The patch for CVE-2019-17026 comes seven months after Mozilla expanded on a pair of powerful zerodays that attackers exploited in an attempt to install an undetected backdoor on Mac computers used by cryptocurrency exchange Coinbase.
While details of the new exploits are not available, Firefox users should install the patch as soon as possible. The easiest way to do this is to use the in-browser update feature, which is available by clicking the “About Firefox” button. On Windows, it is available in the Help section of the menu. On Mac, it is located in the Firefox section of the menu.
