Skip to main content

The U.S. government says you need to update Firefox right now

If you use the Mozilla Firefox web browser, the government recommends that you update the browser because of a zero-day vulnerability that could enable hackers to take control of your computer. 

The United States Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) is encouraging those with the Firefox browser to update to versions 72.0.1 and ESR 68.4.1.

“Mozilla has released security updates to address a vulnerability in Firefox and Firefox ESR. An attacker could exploit this vulnerability to take control of an affected system. This vulnerability was detected in exploits in the wild,” CISA’s statement published on Wednesday reads. 

Mozilla is aware of the vulnerability and issued a fix for it in the latest update version on Wednesday, January 8. The zero-day vulnerability (CVE-2019-17026) was labeled by the company as “critical” and could have allowed potential hackers an open door to access people’s browsers and computers. The company said that hackers actively engaging in “targeted attacks” against the exploit, meaning you could be at serious risk if you don’t update your browser as soon as possible. 

Mozilla said that Chinese cybersecurity firm Qihoo 360 found and reported the vulnerability to the company.

According to Forbes, a zero-day vulnerability means “a security vulnerability that is not known to the product vendor or security researchers but, crucially, is known to threat actors who can then exploit it.”

How to update Firefox

Updating your Firefox browser to protect you from this vulnerability is simple: 

  1. Go to your browser’s menu bar and click About Firefox.
  2. A new window will open and will begin to check for any updates, downloading them automatically.
  3. Once the download is complete, be sure to click Restart to update Firefox to make sure you are using the latest version (72.0.1). 

Despite this vulnerability, Firefox is a close runner-up to Google Chrome for Digital Trends’ pick for the best web browser. Firefox is more privacy-centric than Chrome and is comparably fast. 

Firefox has made recent updates in the last month that include better privacy protections with anti-tracker support, improved password syncing across devices, and integrated breach alerts.

In November, Firefox also made an update in Firefox 70 that allows you to hide notification permission pop-ups that can get annoying. 

Digital Trends reached out to Mozilla to find out more about the vulnerability, and what could have caused it. We will update this story once we hear back. 

Editors' Recommendations

Allison Matyus
Former Digital Trends Contributor
Allison Matyus is a general news reporter at Digital Trends. She covers any and all tech news, including issues around social…
The war between PC and console is about to heat up again
Intel NUC 12 Enthusiast sitting on a desk.

There's no question that consoles are increasingly becoming more like PCs, but thanks to Nvidia, it appears that the opposite may be taking place too.

According to a new report by Wccftech, Nvidia is working with its partners to create a new ecosystem for gaming on small form factor (SFF) PCs. When it comes to Nvidia, many of us think of some of the best graphics cards that are as powerful as they are massive, like the RTX 4090. However, Nvidia is planning to flip that narrative and set its sights on an unexpected target.

Read more
Buying a Steam Deck has never been cheaper
Steam Deck over a pink background.

Valve is serving up huge price cuts on the Steam Deck, but there's a catch -- the consoles are refurbished. Part of the Certified Refurbished Steam Deck program, these handhelds have been fixed up by Valve to reportedly run like new -- and they're significantly cheaper. You can save up to $90, but is this too good to be true? It doesn't have to be.

Buying refurbished devices and hardware can be scary, but when the goodies come directly from the manufacturer, it becomes less risky. This is the case with Valve, which is now selling all three models of the LCD Steam Deck, refurbished and at a price cut. If this sounds good, you can now grab the base model for $279 instead of $349 ($70 savings), while the 256GB NVMe model costs $319 instead of $399 when purchased new. Lastly, the top handheld in the lineup with 512GB of storage costs just $359 instead of $449, which is $90 in savings.

Read more
AMD’s upcoming APUs might destroy your GPU
AMD CEO Lisa Su holding an APU chip.

The spec sheets for AMD's upcoming APU lineups, dubbed Strix Point and Strix Halo, have just been leaked, and it's safe to say that they're looking pretty impressive. Equipped with Zen 5 cores, the new APUs will find their way to laptops that are meant to be on the thinner side, but their performance might rival that of some of the best budget graphics cards -- and that's without having a discrete GPU.

While AMD hasn't unveiled Strix Point (STX) and Strix Halo (STX Halo) specs just yet, they were leaked by HKEPC and then shared by VideoCardz. The sheet goes over the maximum specs for each APU lineup, the first of which, Strix Point, is rumored to launch this year. Strix Halo, said to be significantly more powerful, is currently slated for a 2025 release.

Read more