Patch Firefox right now to fix this zero-day security flaw

(Image credit: Omar Marques/SOPA Images/LightRocket via Getty Images)

If you use Mozilla Firefox, stop what you're doing and check to make sure your version of the popular web browser is 72.0.1, or 68.4.1 if you're using the extended support release (ESR) build.

That's because just a couple of days after releasing Firefox 72 and Firefox ESR 68.4, Mozilla learned that Qihoo 360 researchers found a serious security flaw that, according to the U.S. Department of Homeland Security, could let an attacker "exploit this vulnerability to take control of an affected system."

That is indeed what is already happening, Mozilla said in its advisory posted yesterday (Jan. 8): "We are aware of targeted attacks in the wild abusing this flaw."

Mozilla isn't saying much else other than this is related to an error in the just-in-time JavaScript code compiler for Firefox. John E. Dunn over at Sophos' Naked Security blog has an informative deep dive about what that means.

It's also telling what Mozilla left out of this security advisory: any mention that this might be specific to one operating system. (Compare that to the two previous Mozilla security advisories, which both specified Windows.) Until we learn otherwise, we have to assume that this flaw affects Windows, macOS and Linux alike.

To check your version of Firefox, go to Help --> About Firefox on Windows, or Firefox --> About Firefox on a Mac. Many instances of Firefox update automatically when you launch them, so if you did so this morning, you may have versions 72.0.1 or ESR 68.4.1 already. 

If not, checking the version number gives you the opportunity to check for updates, or often just starts the update process on its own.

TOPICS
Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Latest in Browsers
iPhone 16 Pro Max shown in hand
Your iPhone has a custom voice command feature — here's how to use it
iPhone 16 Pro Max shown in hand
You can change your iPhone's default browser — here's how
Google Chrome on Android
How to stop your personal data from appearing in Google searches
Opera Air
I just tested the world’s first mindful browser — it’s calmly convinced me to ditch Google Chrome
A photo of the Google Chrome logo on a white background, displayed on the screen of a large MacBook Pro which is situated on a table with green foliage behind.
Google Chrome just got three new modes — and it's a game changer for performance
Google Calendar app on iPhone
Google Calendar just got the dark mode we’ve been waiting for — here’s how to activate it
Latest in News
NFL Sunday Ticket logo for YouTube
NFL Sunday Ticket 2025 pricing revealed — and it's bad news
Diego Luna as Cassian Andor in "Andor" season 2 trailer
New ‘Andor’ season 2 trailer teases more explosive action and a darker edge to the hit ‘Star Wars’ show
Russian flag with padlock smashing through glass
47 VPNs could be axed from Google Play Store following Russian demands
ChatGPT on iPhone
ChatGPT was down — updates on quick outage
Emma D'Arcy in House of the Dragon season 2
‘House of the Dragon’ season 3 has officially begun filming — what it could mean for the potential release window
AirPods Max in various colors
AirPods Max is getting a big update with lossless audio and ultra-low latency — here's how it works