Mozilla has swiftly patched a pair of critical Firefox zero-days after a researcher debuted them at a Vancouver cybersec competition. Manfred Paul demonstrated the bugs at Pwn2Own last week, the latest in the series of vulnerability and exploit events run by Trend Micro's Zero Day Initiative (ZDI). The event had security experts vying to exploit the most vulnerabilities across the competition, earning cash prizes and league table points for each success. Paul exploited two vulnerabilities, both of which were rated "critical," which is to say they are each thought to carry a severity score of 9.0 or above, although specific ratings are yet to be assigned. They're now tracked as CVE-2024-29943 and CVE-2024-29944 – an an out-of-bounds read/write and a privileged code execution bug respectively. The full descriptions per Mozilla's advisory: CVE-2024-29943: An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination CVE-2024-29944: An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox The way Pwn2Own works is that researchers demonstrate how their exploit works against a target product. If it's successful, they then go into a backroom to verify it works and isn't already known to the vendor. Each event typically has a th...
Mozilla fixes $100,000 Firefox zero-days following two-day hackathon
The Register
·Connor Jones
·Published Mar 25, 2024
·Updated
Affected Software
2 affected components
Mozilla Firefox=124
Mozilla Firefox=124.0.1