Critical Vulnerabilities in Firefox, Firefox ESR, and Thunderbird
Sunday, 22 May, 2022 |
|
Mozilla has released critical security updates for Firefox, Firefox ESR, and Thunderbird, addressing critical vulnerabilities. Most severe of discovered vulnerabilities could allow remote code execution on successful exploitation.
A remote attacker can persuade a victim to visit a specially constructed website, corrupt the methods of an Array object in JavaScript via prototype pollution, and run arbitrary JavaScript code in a privileged context, potentially allowing an attacker to compromise the system.
