Daily Archives: April 30, 2025

  • Security fixes for Firefox

    Firefox Logo Firefox released a browser update on April 29. It includes security fixes as well as enhancements. There is a new profile manager as well as unique features that are only available in the United States. It’s always interesting to see how software manufacturers must navigate the different mandates from various locations.

    I found it interesting that Firefox is also facing bugs in its updater service. As noted in a Mozilla Foundation Security Advisory:

    Mozilla Firefox’s update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation.