Close Menu
Luminari | Learn Docker, Kubernetes, AI, Tech & Interview PrepLuminari | Learn Docker, Kubernetes, AI, Tech & Interview Prep
  • Home
  • Technology
    • Docker
    • Kubernetes
    • AI
    • Cybersecurity
    • Blockchain
    • Linux
    • Python
    • Tech Update
    • Interview Preparation
    • Internet
  • Entertainment
    • Movies
    • TV Shows
    • Anime
    • Cricket
What's Hot

Armenia Crime Drama Film ‘Thus Spoke the Wind’ Trailer: KVIFF 2025

June 4, 2025

Your Score: Simulcast Week of 2025-05-26

June 4, 2025

Blockchain can end the food fraud crisis, but it’s a costly battle

June 4, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Luminari | Learn Docker, Kubernetes, AI, Tech & Interview Prep
  • Home
  • Technology
    • Docker
    • Kubernetes
    • AI
    • Cybersecurity
    • Blockchain
    • Linux
    • Python
    • Tech Update
    • Interview Preparation
    • Internet
  • Entertainment
    • Movies
    • TV Shows
    • Anime
    • Cricket
Luminari | Learn Docker, Kubernetes, AI, Tech & Interview PrepLuminari | Learn Docker, Kubernetes, AI, Tech & Interview Prep
Home » Firefox Patches 2 Zero-Days Exploited at Pwn2Own Berlin with $100K in Rewards
Cybersecurity

Firefox Patches 2 Zero-Days Exploited at Pwn2Own Berlin with $100K in Rewards

HarishBy HarishMay 19, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
Share
Facebook Twitter Pinterest Reddit WhatsApp Email


May 19, 2025Ravie LakshmananBrowser Security / Vulnerability

Mozilla has released security updates to address two critical security flaws in its Firefox browser that could be potentially exploited to access sensitive data or achieve code execution.

The vulnerabilities, both of which were exploited as a zero-day at Pwn2Own Berlin, are listed below –

CVE-2025-4918 – An out-of-bounds access vulnerability when resolving Promise objects that could allow an attacker to perform read or write on a JavaScript Promise object
CVE-2025-4919 – An out-of-bounds access vulnerability when optimizing linear sums that could allow an attacker to perform read or write on a JavaScript object by confusing array index sizes

In other words, successful exploitation of either of the flaws could permit an adversary to achieve out-of-bounds read or write, which could then be abused to access otherwise sensitive information or result in memory corruption that could pave the way for code execution.

Cybersecurity

The vulnerabilities affect the following versions of the Firefox browser –

Edouard Bochin and Tao Yan from Palo Alto Networks have been credited with finding and reporting CVE-2025-4918. The discovery of CVE-2025-4919 has been credited to Manfred Paul.

It’s worth noting that both shortcomings were demonstrated at the Pwn2Own Berlin hacking contest last week for which they were awarded $50,000 each.

With web browsers continuing to be an attractive vector for malware delivery, users are advised to update their instances to the latest version to safeguard against potential threats.

“Neither of the attacks managed to break out of our sandbox, which is required to gain control over the user’s system,” Mozilla said in a statement. “Despite the limited impact of these attacks, all users and administrators are advised to update Firefox as soon as possible.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



Source link

Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
Previous ArticleLive updates: Sean ‘Diddy’ Combs trial continues after Cassie Ventura’s testimony
Next Article Cannes biggest events All Happened At the Carlton hotel
Harish
  • Website
  • X (Twitter)

Related Posts

HPE Issues Security Patch for StoreOnce Bug Allowing Remote Authentication Bypass

June 4, 2025

Fake DocuSign, Gitcode Sites Spread NetSupport RAT via Multi-Stage PowerShell Attack

June 3, 2025

Critical 10-Year-Old Roundcube Webmail Bug Allows Authenticated Users Run Malicious Code

June 3, 2025

Understanding Help Desk Scams and How to Defend Your Organization

June 3, 2025

Android Trojan Crocodilus Now Active in 8 Countries, Targeting Banks and Crypto Wallets

June 3, 2025

Google Chrome to Distrust Two Certificate Authorities Over Compliance and Conduct Issues

June 3, 2025
Add A Comment
Leave A Reply Cancel Reply

Our Picks

Armenia Crime Drama Film ‘Thus Spoke the Wind’ Trailer: KVIFF 2025

June 4, 2025

Your Score: Simulcast Week of 2025-05-26

June 4, 2025

Blockchain can end the food fraud crisis, but it’s a costly battle

June 4, 2025

SEC to police crypto with ‘notice and comment rulemaking’

June 4, 2025
Don't Miss
Blockchain

Blockchain can end the food fraud crisis, but it’s a costly battle

June 4, 20257 Mins Read

Food fraud siphons up to $50 billion from the global food industry every year and…

SEC to police crypto with ‘notice and comment rulemaking’

June 4, 2025

Trumps deny involvement in Trump-branded memecoin wallet

June 4, 2025

Tokenized funds hit $5.7B, scaling fast — Moody’s

June 3, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to Luminari, your go-to hub for mastering modern tech and staying ahead in the digital world.

At Luminari, we’re passionate about breaking down complex technologies and delivering insights that matter. Whether you’re a developer, tech enthusiast, job seeker, or lifelong learner, our mission is to equip you with the tools and knowledge you need to thrive in today’s fast-moving tech landscape.

Our Picks

One of Africa’s most successful founders is back with a new AI startup and already raised $9M

June 4, 2025

Windsurf says Anthropic is limiting its direct access to Claude AI models

June 4, 2025

Anthropic’s AI is writing its own blog — with human oversight

June 3, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 luminari. Designed by luminari.

Type above and press Enter to search. Press Esc to cancel.