

The exploit is in the wild, meaning it’s now public and every hacker on the planet has access to it. The vulnerability allows an attacker to execute code on your Windows workstation.

If you use Firefox, we recommend you temporarily switch browsers to Chrome, Safari or a non-firefox based browser that is secure until the Firefox dev team can release an update. Currently it exploits Windows systems with a high success rate and affects Firefox versions 41 to 50 and the current version of the Tor Browser Bundle which contains Firefox 45 ESR. A few hours ago a zero day vulnerability emerged in the Tor browser bundle and the Firefox web browser. We’re publishing this as an emergency bulletin for our customers and the larger web community. I also posted an extended update at the end of the post including data indicating this exploit may be part of a law enforcement operation. Tor have also released a fix with version 6.0.7 of their browser.There is also a Thunderbird fix out, version 45.5.1. Update to Firefox 50.0.2 now to patch this vulnerability. Update at 2:32pm PST / 5:32pm EST: Firefox released a fix for this a few minutes ago. Tor Browser 6.0.7, Firefox 45.5.1esr, NoScript 2.9.5.2.Emergency Bulletin: Firefox 0 day in the wild. After installing and restarting Tor, the following version information should be shown. Selecting the Tor icon in symbol bar and click the "Search for update" command reports a pending update. I just checked the Tor browser under Windows. Also Thunderbird has been updated to 45,5.1. So we have updates for Firefox to 50.0.2 and the ESR version to 45.5.1. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. #CVE-2016-9079: Use-after-free in SVG AnimationĪ use-after-free vulnerability in SVG Animation has been discovered. Mozilla Foundation Security Advisory 2016-92 Firefox SVG Animation Remote Code Execution ANNOUNCED NovemPRODUCTS Firefox, Firefox ESR, Thunderbird FIXED IN The announcement has been made at this Mozilla page. This night Mozilla's developer has released a security update for Firefox and Thunderbird. Yesterday I reported a zero-day-vulnerability in Tor and Firefox browser – see Firefox Zero-day exploit puts Tor users at risk.
