Skip to main content
  1. Home
  2. Computing
  3. News

Firefox users, update your browser: Mozilla has found and fixed a new vulnerability

Add as a preferred source on Google

It isn’t at all unusual to hear about a newly unearthed browser vulnerability, but it’s slightly less common to hear at the same time that it’s already been fixed. Firefox users, it’s time to update your browser.

On Wednesday, Mozilla was informed by a Firefox user that an advertisement on a Russian news site was exploiting a previously unknown vulnerability in the browser, Daniel Veditz wrote on the Mozilla Security Blog. The exploit used the vulnerability to search the user’s computer for files that, once found, would be uploaded to a server that appeared to be located in Ukraine.

Recommended Videos

The exploit, like some other recently found vulnerabilities, involves the PDF format. Specifically, the vulnerability lies in the interaction between the browser’s “same origin policy” and Firefox’s built-in PDF viewer. Veditz notes that browsers that don’t contain the PDF viewer, like Firefox for Android, aren’t vulnerable to the exploit.

While the exploit itself didn’t allow the attacker to run arbitrary code, it did allow the injecting of a JavaScript file that would then run on the targeted system. Surprisingly, the script doesn’t search for personal data, but developer-focused files like configuration files for subversion, s3browser, Filezilla, and eight popular FTP clients. For more details on the exploit, see the full post on the Mozilla Security Blog.

Luckily, Mozilla was quick on the draw, and has already fixed the vulnerability. The fix is available in Firefox 39.0.3, and naturally Mozilla is urging all users to update. The vulnerability has also been fixed in Firefox ESR 38.1.1.

The exploit only targeted Windows and Linux users, but that doesn’t necessarily mean that Mac users have nothing to fear. Veditz writes that ” Mac users are not targeted by this particular exploit but would not be immune should someone create a different payload.”

If you use Firefox on a Windows or Linux machine, Mozilla recommends changing any passwords and security keys for programs targeted by the exploit. Veditz notes that ad-blocking software may have protected some users, but this isn’t a given, so you’re still better off updating Firefox.

Kris Wouk
Former Contributor
Kris Wouk is a tech writer, gadget reviewer, blogger, and whatever it's called when someone makes videos for the web. In his…
Claude Opus 5 is here, and Anthropic says it can rival Fable 5 in some tasks
Major software engineering improvements put Opus 5 closer to Anthropic’s top model
Claude Opus 5 logo

Anthropic has launched Claude Opus 5, its latest frontier AI model for coding, research, business work, and other complex tasks. The company says it delivers a major performance jump over Claude Opus 4.8 while keeping the same API price. Anthropic also claims it comes close to Claude Fable 5 on some coding and computer-use tests while costing far less per task.

Opus 5 is available across Claude’s apps and API. It is now the default model for Claude Max subscribers and the strongest option included with Claude Pro.

Read more
Humans actually prefer talking to an AI than a support person, says gas giant as it cuts jobs
British Gas cuts 1,300 support jobs as its CEO points to changing customer habits
Executive, Person, Electronics

Centrica, owner of British Gas, is cutting 1,300 call centre jobs, and its chief executive says changing customer behaviour is the main reason. The company plans to remove 800 roles as part of a “targeted deployment of AI tools,” on top of the 500 cuts announced last month. Customer service teams in Glasgow, Edinburgh, Cardiff, Leicester, Stockport, and Leeds will be affected over the next two years.

Some positions will disappear when employees leave and are not replaced, while the remaining cuts will come through redundancies. Trade unions have warned that Centrica’s AI investment will hand hundreds of human jobs to chatbots.

Read more
Intel just pulled its 14A production schedule forward by a year
Risk production for 14A is now planned for late 2027
Intel Core Ultra Desktop CPU

Intel has moved up the schedule for its next-generation 14A (1.4-nanometer) manufacturing process, giving its foundry turnaround an important new target.

During Intel’s Q2 2026 earnings call, CEO Lip-Bu Tan said 14A risk production for internal products is now planned for the second half of 2027. High-volume production is expected to begin in 2028. This is earlier than the previous timeline, when Intel was expected to begin risk production in 2028 and move to volume production in 2029.

Read more