this post was submitted on 16 Oct 2024
74 points (100.0% liked)

technology

23332 readers
118 users here now

On the road to fully automated luxury gay space communism.

Spreading Linux propaganda since 2020

Rules:

founded 4 years ago
MODERATORS
 

In case someone missed this (i did :(, story from a week ago), forks also should be updated by now meow-floppy

Mozilla has revealed that a critical security flaw impacting Firefox and Firefox Extended Support Release (ESR) has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2024-9680 (CVSS score: 9.8), has been described as a use-after-free bug in the Animation timeline component.

The issue has been addressed in the following versions of the web browser -

Firefox 131.0.2
Firefox ESR 128.3.1, and
Firefox ESR 115.16.1.
top 13 comments
sorted by: hot top controversial new old
[–] [email protected] 19 points 1 month ago (1 children)

Supposedly Windows users are safe. Which blows my mind because Windows is usually the least safe.

[–] Dudewitbow 12 points 1 month ago (3 children)

windows was only the least safe because it had the largest user marketshare, therefore was more effective to target them.

in the age where less people are using pcs and optimg for mobile, it makes more sense to target mobile, especially since its way more likely to have sensitive information than an arbitrary computer would.

[–] [email protected] 15 points 1 month ago

Contemporary phones are intentionally portable tracking and data collection and transmission devices, all ignoring and not really asking for the consent of the buyer.

It fucking sucks.

[–] [email protected] 7 points 1 month ago
[–] [email protected] 4 points 1 month ago

Windows was the largest and it sucked at security. It’s better today but the reputation is still well deserved.

[–] [email protected] 11 points 1 month ago (2 children)

This says 131.0.2 was out on october 9th, which is the day before the article you posted, hopefully we're all good

https://www.mozilla.org/en-US/firefox/131.0.2/releasenotes/

mine had already updated to 131.0.3

[–] [email protected] 8 points 1 month ago (1 children)

Its mainly reminder for forks, like zen, librewolf etc. Or those who break autoupdate like me

[–] [email protected] 4 points 1 month ago

Its good you posted! I was just commenting to add additional info.

[–] [email protected] 3 points 1 month ago

mine had already updated to 131.0.3

Yeah I checked mine and it's updated to the same, I got super scared for a moment.

[–] [email protected] 4 points 1 month ago* (last edited 1 month ago)

Has flatpak Firefox been updated yet? Last time I checked it was still (I think) 131.0 but that was a few days ago.

[–] [email protected] 3 points 1 month ago (2 children)

I assume this also affects mobile Firefox like Firefox/Fennec for Android? The version of Fennec on F-Droid is like 2 months old.

[–] [email protected] 2 points 1 month ago

I haven't seen mentions of mobile anywhere soviet-hmm maybe its sufficiently different?