Photo of Mozilla Logo n Smartphone with Mozilla Website in the Background
© T. Schneider/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

Threat actors can exploit vulnerabilities in older versions of Mozilla’s Firefox browser and Thunderbird email client to take over affected devices, the U.S. Cybersecurity & Infrastructure Security Agency (CISA) warned on Wednesday.

Mozilla has released security patches to fix the vulnerabilities. We strongly recommend updating your Firefox and Thunderbird apps to the latest version to protect your privacy.

‘High-Severity’ Vulnerabilities

Mozilla Firefox 120, released on Tuesday, fixes several high-severity vulnerabilities. In a security advisory, Mozilla said one of the vulnerabilities — tracked as CVE-2023-6206 — allows threat actors to launch clickjacking attacks.

Clickjacking is a malicious technique where cybercriminals trick users into clicking something different from what they intend to click on.

By overlaying deceptive prompts, attackers can trick users into unwittingly granting permissions or disclosing confidential information. The vulnerability allowed threat actors to launch clickjacking attacks during the transition when exiting fullscreen mode.

“The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear,” Mozilla security advisory said.

Protecting Your System From Security Vulnerabilities

It’s not uncommon for experts to uncover security vulnerabilities in popular software. To protect your device from these threats, users are advised to:

  • Update immediately: Ensure your Firefox, Firefox for iOS, and Thunderbird apps are updated to their latest versions.
  • Stay informed: Regularly check for security advisories from Mozilla and CISA.
  • Practice safe browsing: Be cautious of unsolicited permission prompts and avoid clicking on suspicious links.
  • Use security tools: Install a premium antivirus and use a top-rated VPN, like NordVPN, to add an extra layer of protection.

Refer to the Firefox and Thunderbird support documents to find out how to update these respective software on your operating system. It is important to do so, especially as threat actors are known to be highly active during Black Friday, Cyber Monday, and the holiday season.

For more news, follow us on X (Twitter), Threads, and Mastodon!

Leave a comment