Mozilla bug may let hackers target Firefox for Android browsers


New Delhi, Sep 19 (IANS): Mozilla has fixed a vulnerability in the popular Firefox browser that can be exploited by hackers to hijack Firefox for Android browsers on the same WiFi network and send users to malicious sites, urging the people to install the latest browser update.

The bug was found in Firefox SSDP component by Chris Moberly, an Australian security researcher working for GitLab, reports ZDNet.

The Simple Service Discovery Protocol (SSDP) is a simple protocol designed to solve the problem of service discovery over a local network.

"Any Android owner using a Firefox browser to navigate the web during this kind of attack would have his mobile browser hijacked and taken to a malicious site, or forced to install a malicious Firefox extension," the report mentioned.

The bug has been fixed in Firefox 79.

Mozilla said users should update as soon as possible to Firefox v79 for Android to remain safe.

Attackers could leverage exploits to take over outdated routers, and then spam a company's internal network and force employees to re-authenticate on phishing pages.

The new Firefox for Android now offers Enhanced Tracking Protection (ETP), providing a better web experience.

"The revamped browsing app comes with our highest privacy protections ever – on by default. ETP keeps numerous ad trackers at bay and out of the users' business," the company said last month.

The Enhanced Tracking Protection automatically blocks many known third-party trackers, by default, in order to improve user privacy online. Private Mode adds another layer for better privacy on device level, it added.

 

  

Top Stories


Leave a Comment

Title: Mozilla bug may let hackers target Firefox for Android browsers



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.