The last Nightly Firefox build for Android to date is 68.0.a1 from 2019-05-04. https://www.mozilla.org/en-US/firefox/android/nightly/all/ Does it contain the fix?
I asked on twitter and they said nightly was not affected. https://mobile.twitter.com/FirefoxNightly/status/11411120523...
Mozilla patches Firefox zero-day abused in the wild
61–70 of 111 posts
Re: Mozilla patches Firefox zero-day abused in the wild
#62The last Nightly Firefox build for Android to date is 68.0.a1 from 2019-05-04. https://www.mozilla.org/en-US/firefox/android/nightly/all/ Does it contain the fix?
Looks like nightly builds aren't being published. Even if you browse the directories manually, they're not there[1]. On google play[2] it's showing as updated, though. [1] https://download-installer.cdn.mozilla.net/pub/mobile/nightl... although the ESR builds are coming in fine, so maybe something broke the build script? [2] https://play.google.com/store/apps/details?id=org.mozilla.fe...
> Is Mozilla Firefox ESR available for Android and iOS?
> No. Firefox ESR will only be offered for Windows, macOS and Linux for desktop computers.
Play Store is confusing, because the actual version is "depends on your device".
Re: Mozilla patches Firefox zero-day abused in the wild
#63Firefox is supposed to have sandboxing, right? Does this sandboxing help against such attacks? As in: is there a second attack on the sandbox needed to get RCE?
Re: Mozilla patches Firefox zero-day abused in the wild
#64Earlier quoted context omitted.
I asked on twitter and they said nightly was not affected. https://mobile.twitter.com/FirefoxNightly/status/11411120523...
That's kind of strange, especially considering the fact Nightly Android and Nightly Desktop are different versions.
Re: Mozilla patches Firefox zero-day abused in the wild
#65Earlier quoted context omitted.
Looks like nightly builds aren't being published. Even if you browse the directories manually, they're not there[1]. On google play[2] it's showing as updated, though. [1] https://download-installer.cdn.mozilla.net/pub/mobile/nightl... although the ESR builds are coming in fine, so maybe something broke the build script? [2] https://play.google.com/store/apps/details?id=org.mozilla.fe...
While official ESR FAQ say there's no ESR for Android ever. > Is Mozilla Firefox ESR available for Android and iOS? > No. Firefox ESR will only be offered for Windows, macOS and Linux for desktop computers. Play Store is confusing, because the actual version is "depends on your device".
Re: Mozilla patches Firefox zero-day abused in the wild
#66Earlier quoted context omitted.
True they could have been clearer on the versions affected, but tbh you should keep with the latest supported anyway. Security bug reports are often restricted for some time after a new release to help prevent reverse engineering to find the bug.
Please do not assume people are not running current release just because they are lazy and have not upgraded. The user experience was degraded at FF57 for many individuals who need extensions that will not work with ff>56 or that developers have abandoned out of frustration with Mozilla. When all the extensions I find necessary are functional (or with suitable replacements) I will switch.
Doubly so when the advice given is basically "bend over and take it" --- especially when Mozilla has made statements like this in the past:
https://blog.mozilla.org/security/2013/01/29/putting-users-i...
"Users should have the choice of what software and plugins run on their machine."
In any case, I hope NoScript is one of the extensions you're already using, because this is another vulnerability that requires JS to exploit. JS off by default already gets rid of the vast majority of them.
Re: Mozilla patches Firefox zero-day abused in the wild
#67It's a JIT bug, you can see the fix here: https://hg.mozilla.org/releases/mozilla-release/rev/99a829d2...
If the bug is really that old, it's certainly possible it might have been abused in the wild, perhaps in more ways than the just the "targeted attacks" mentioned the report.
[1] https://hg.mozilla.org/releases/mozilla-release/rev/99a829d2...
[2] https://hg.mozilla.org/releases/mozilla-release/rev/6bfcb81d...
Re: Mozilla patches Firefox zero-day abused in the wild
#68Someone I know was hit by this in a very targeted attack on June 6th. They managed to capture the binary it dropped on their mac with some other gatekeeper bypass vulnerability (perhaps https://www.bleepingcomputer.com/news/security/new-unpatched... ). It is a mac port of the binary discussed in this research paper by Exatel: https://exatel.pl/advisory/paranoicy-raport-socexatel.pdf
Sounds extremely targeted, if an attacker is porting the attack to Macs (presumably a lot of work), and combining it with other loaders... I wonder how long this 0-day was in the wild. Your friend should probably be browsing as a non-admin in a continuously-reimaged VM, separate from an air-gapped machine, if you have those kinds of attackers after you. Spooky..
How come?
Re: Mozilla patches Firefox zero-day abused in the wild
#69Earlier quoted context omitted.
Please do not assume people are not running current release just because they are lazy and have not upgraded. The user experience was degraded at FF57 for many individuals who need extensions that will not work with ff>56 or that developers have abandoned out of frustration with Mozilla. When all the extensions I find necessary are functional (or with suitable replacements) I will switch.
This is exactly the problem with the culture that's formed around software and the security industry in general --- people are using the excuse of "security" to force other utterly unwanted and hostile changes, and then act surprised and angry when people don't update. Doubly so when the advice given is basically "bend over and take it" --- especially when Mozilla has made statements like this in the past: https://bl…