The U.S. government says you need to update Firefox right now

If you use the Mozilla Firefox web browser, the government recommends that you update the browser because of a zero-day vulnerability that could enable hackers to take control of your computer. 

The United States Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) is encouraging those with the Firefox browser to update to versions 72.0.1 and ESR 68.4.1.

Recommended Videos

“Mozilla has released security updates to address a vulnerability in Firefox and Firefox ESR. An attacker could exploit this vulnerability to take control of an affected system. This vulnerability was detected in exploits in the wild,” CISA’s statement published on Wednesday reads. 

Mozilla is aware of the vulnerability and issued a fix for it in the latest update version on Wednesday, January 8. The zero-day vulnerability (CVE-2019-17026) was labeled by the company as “critical” and could have allowed potential hackers an open door to access people’s browsers and computers. The company said that hackers actively engaging in “targeted attacks” against the exploit, meaning you could be at serious risk if you don’t update your browser as soon as possible. 

Mozilla said that Chinese cybersecurity firm Qihoo 360 found and reported the vulnerability to the company.

According to Forbes, a zero-day vulnerability means “a security vulnerability that is not known to the product vendor or security researchers but, crucially, is known to threat actors who can then exploit it.”

How to update Firefox

Updating your Firefox browser to protect you from this vulnerability is simple: 

  1. Go to your browser’s menu bar and click About Firefox.
  2. A new window will open and will begin to check for any updates, downloading them automatically.
  3. Once the download is complete, be sure to click Restart to update Firefox to make sure you are using the latest version (72.0.1). 

Despite this vulnerability, Firefox is a close runner-up to Google Chrome for Digital Trends’ pick for the best web browser. Firefox is more privacy-centric than Chrome and is comparably fast. 

Firefox has made recent updates in the last month that include better privacy protections with anti-tracker support, improved password syncing across devices, and integrated breach alerts.

In November, Firefox also made an update in Firefox 70 that allows you to hide notification permission pop-ups that can get annoying. 

Digital Trends reached out to Mozilla to find out more about the vulnerability, and what could have caused it. We will update this story once we hear back. 

Editors' Recommendations

Former Digital Trends Contributor
Allison Matyus is a general news reporter at Digital Trends. She covers any and all tech news, including issues around social…
We finally know the price of Asus’ most powerful gaming NUC

The first Asus ROG NUC (Next Unit of Computing) model is just around the corner. The small form factor PC is now up for pre-order at a German retailer, and although it's powerful enough to rival some of the best laptops, it costs more than many comparable models -- and you'll still have to pay extra for a monitor.

Asus' first take on Intel's portable PC contains a lot of compute power in a small chassis. Although there are a few configurations of the PC, the one that was spotted up for sale ahead of time comes with Intel's latest Meteor Lake-H CPU, the Core Ultra 9 185H, which sports 16 cores and 22 threads and can be boosted to run at up to 5.1GHz, all with a thermal design power (TDP) of 45 watts. However, Asus allows overclocking, meaning that the CPU can run at up to 65 watts instead.

Read more
YouTube tells creators to start labeling ‘realistic’ AI content

YouTube is taking steps to try to help viewers better understand if what they’re watching has been created, whether completely or in part, by generative AI.

“Generative AI is transforming the ways creators express themselves -- from storyboarding ideas to experimenting with tools that enhance the creative process,” YouTube said in a message shared on Monday. “But viewers increasingly want more transparency about whether the content they’re seeing is altered or synthetic.”

Read more
AMD is making the CPU more and more obsolete in gaming

At GDC 2024, AMD just expanded on Microsoft's recently announced Work Graphs API, and a quick demo shows just how powerful the new tech can be for gaming performance. AMD's iteration moves draw calls and mesh nodes from the CPU to the GPU, cutting back on the time it takes to execute these tasks. As a result, AMD found that there was a massive performance improvement -- rendering time saw a 64% boost -- when using Work Graphs with mesh shaders.

Microsoft introduced Work Graphs as a way to streamline processes both in gaming and in productivity, all by giving the GPU the power to schedule and execute tasks without first communicating with the CPU. It's built into the Direct3D 12 API and it can reduce bottlenecks and improve gaming performance in 3D games.

Read more