Security News > 2020 > January > Mozilla Patches Firefox Zero-Day Exploited in Targeted Attacks

Updates released by Mozilla on Wednesday for its Firefox browser address a zero-day vulnerability that has been exploited in targeted attacks.
Mozilla says it's aware of targeted attacks exploiting this zero-day, but no other information has been made available.
The flaw has been patched with the release of Firefox 72.0.1 and Firefox ESR 68.4.1, and users have been advised to update their installations.
Mozilla last year patched two Firefox zero-day vulnerabilities that had been exploited to deliver Mac malware to cryptocurrency exchanges.
Firefox 72 also patches nearly a dozen vulnerabilities, including 5 rated high severity.
News URL
Related news
- Mozilla Patches Critical Firefox Bug Similar to Chrome’s Recent Zero-Day Vulnerability (source)
- Mozilla fixes Firefox zero-days exploited at hacking contest (source)
- Zero-Day Alert: Google Releases Chrome Patch for Exploit Used in Russian Espionage Attacks (source)
- Mozilla warns Windows users of critical Firefox sandbox escape flaw (source)
- After Chrome patches zero-day used to target Russians, Firefox splats similar bug (source)
- Google fixes Android zero-days exploited in attacks, 60 other flaws (source)
- Apple fixes two zero-days exploited in targeted iPhone attacks (source)
- Apple plugs zero-day holes used in targeted iPhone attacks (CVE-2025-31200, CVE-2025-31201) (source)
- Apple Patches Two Zero-Days Used in ‘Extremely Sophisticated’ Attacks (source)
- Phishing detection is broken: Why most attacks feel like a zero day (source)