Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Firefox Zero-day (CVE-2024-9680) #227

Open
ThatBigDerp opened this issue Oct 11, 2024 · 2 comments
Open

Firefox Zero-day (CVE-2024-9680) #227

ThatBigDerp opened this issue Oct 11, 2024 · 2 comments

Comments

@ThatBigDerp
Copy link

ThatBigDerp commented Oct 11, 2024

Recently Firefox patched the CVE-2024-9680 zero-day in the following versions:

  • Firefox 131.0.2
  • Firefox ESR 128.3.1
  • Firefox ESR 115.16.1

Currently Mercury is based on Firefox 192.0.02 which means it's vulnerable. My suggestion is due to low update activity to switch to Firefox's ESR release due to their slower, but more stable release cycle also reducing the need for you to update Mercury, if not at least update the browser to the latest Firefox version with the vulnerabilities patched, because according to Mozilla the vulnerability is already being exploited.

@gz83
Copy link
Collaborator

gz83 commented Oct 11, 2024

We will update as quickly as possible, but the disclosed vulnerabilities do not immediately put your device at risk.

@ridwanpr
Copy link

ridwanpr commented Nov 4, 2024

It's been 1 month

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants