FireFox ESR-68.12

For discussions about security.
Post Reply
User avatar
8Geee
Posts: 376
Joined: Wed Jul 29, 2020 10:52 pm
Location: N.E. USA
Has thanked: 16 times
Been thanked: 56 times

FireFox ESR-68.12

Post by 8Geee »

There's a security update at mozilla for the ESR-68 version as #12. One of the snafu's involves this...

#CVE-2020-15664: Attacker-induced prompt for extension installation

Impact
high

Description:
By holding a reference to the eval() function from an about:blank window, a
malicious webpage could have gained access to the InstallTrigger object which
would allow them to prompt the user to install an extension. Combined with user
confusion, this could result in an unintended or malicious extension being installed.

If you work with blank pages (aka: opened and empty tabs for future use) keep this bug in mind. The obvious "fix" is to close all opened and empty tabs.

Regards
8Geee

Money talks... no, it shouts, so that it doesn't have to hear common sense.

Post Reply

Return to “Security”