Close Menu
Luminari | Learn Docker, Kubernetes, AI, Tech & Interview PrepLuminari | Learn Docker, Kubernetes, AI, Tech & Interview Prep
  • Home
  • Technology
    • Docker
    • Kubernetes
    • AI
    • Cybersecurity
    • Blockchain
    • Linux
    • Python
    • Tech Update
    • Interview Preparation
    • Internet
  • Entertainment
    • Movies
    • TV Shows
    • Anime
    • Cricket
What's Hot

Mark Hamill Rules Out ‘Star Wars’ Return: “No Way”

June 2, 2025

This platform simplifies launching privacy-first AI applications for developers

June 2, 2025

World Cup heroics highlight Maxwell’s ODI journey

June 2, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Luminari | Learn Docker, Kubernetes, AI, Tech & Interview Prep
  • Home
  • Technology
    • Docker
    • Kubernetes
    • AI
    • Cybersecurity
    • Blockchain
    • Linux
    • Python
    • Tech Update
    • Interview Preparation
    • Internet
  • Entertainment
    • Movies
    • TV Shows
    • Anime
    • Cricket
Luminari | Learn Docker, Kubernetes, AI, Tech & Interview PrepLuminari | Learn Docker, Kubernetes, AI, Tech & Interview Prep
Home » Firefox Patches 2 Zero-Days Exploited at Pwn2Own Berlin with $100K in Rewards
Cybersecurity

Firefox Patches 2 Zero-Days Exploited at Pwn2Own Berlin with $100K in Rewards

HarishBy HarishMay 19, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
Share
Facebook Twitter Pinterest Reddit WhatsApp Email


May 19, 2025Ravie LakshmananBrowser Security / Vulnerability

Mozilla has released security updates to address two critical security flaws in its Firefox browser that could be potentially exploited to access sensitive data or achieve code execution.

The vulnerabilities, both of which were exploited as a zero-day at Pwn2Own Berlin, are listed below –

CVE-2025-4918 – An out-of-bounds access vulnerability when resolving Promise objects that could allow an attacker to perform read or write on a JavaScript Promise object
CVE-2025-4919 – An out-of-bounds access vulnerability when optimizing linear sums that could allow an attacker to perform read or write on a JavaScript object by confusing array index sizes

In other words, successful exploitation of either of the flaws could permit an adversary to achieve out-of-bounds read or write, which could then be abused to access otherwise sensitive information or result in memory corruption that could pave the way for code execution.

Cybersecurity

The vulnerabilities affect the following versions of the Firefox browser –

Edouard Bochin and Tao Yan from Palo Alto Networks have been credited with finding and reporting CVE-2025-4918. The discovery of CVE-2025-4919 has been credited to Manfred Paul.

It’s worth noting that both shortcomings were demonstrated at the Pwn2Own Berlin hacking contest last week for which they were awarded $50,000 each.

With web browsers continuing to be an attractive vector for malware delivery, users are advised to update their instances to the latest version to safeguard against potential threats.

“Neither of the attacks managed to break out of our sandbox, which is required to gain control over the user’s system,” Mozilla said in a statement. “Despite the limited impact of these attacks, all users and administrators are advised to update Firefox as soon as possible.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



Source link

Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
Previous ArticleLive updates: Sean ‘Diddy’ Combs trial continues after Cassie Ventura’s testimony
Next Article Cannes biggest events All Happened At the Carlton hotel
Harish
  • Website
  • X (Twitter)

Related Posts

Cryptojacking Campaign Exploits DevOps APIs Using Off-the-Shelf Tools from GitHub

June 2, 2025

Qualcomm Fixes 3 Zero-Days Used in Targeted Android Attacks via Adreno GPU

June 2, 2025

APT Intrusions, AI Malware, Zero-Click Exploits, Browser Hijacks and More

June 2, 2025

The Secret Defense Strategy of Four Critical Industries Combating Advanced Cyber Threats

June 2, 2025

Fake Recruiter Emails Target CFOs Using Legit NetBird Tool Across 6 Global Regions

June 2, 2025

New Linux Flaws Allow Password Hash Theft via Core Dumps in Ubuntu, RHEL, Fedora

May 31, 2025
Add A Comment
Leave A Reply Cancel Reply

Our Picks

Mark Hamill Rules Out ‘Star Wars’ Return: “No Way”

June 2, 2025

This platform simplifies launching privacy-first AI applications for developers

June 2, 2025

World Cup heroics highlight Maxwell’s ODI journey

June 2, 2025

Cryptojacking Campaign Exploits DevOps APIs Using Off-the-Shelf Tools from GitHub

June 2, 2025
Don't Miss
Blockchain

This platform simplifies launching privacy-first AI applications for developers

June 2, 20256 Mins Read

Artificial intelligence is quickly moving from a background role to center stage in nearly all…

How to Use Index Funds and ETFs for Passive Crypto Income

June 2, 2025

Polygon NFT sales surpass $2 billion as RWA collections drive 2025 growth

June 2, 2025

Bitopro exchange hit by $11.5M outflows in potential exploit

June 2, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to Luminari, your go-to hub for mastering modern tech and staying ahead in the digital world.

At Luminari, we’re passionate about breaking down complex technologies and delivering insights that matter. Whether you’re a developer, tech enthusiast, job seeker, or lifelong learner, our mission is to equip you with the tools and knowledge you need to thrive in today’s fast-moving tech landscape.

Our Picks

5 days left to claim your exhibitor table for TC All Stage | TechCrunch

June 2, 2025

TC Sessions: AI Trivia Countdown — win big tickets

June 2, 2025

3 days until the doors open at TC Sessions: AI at UC Berkeley

June 2, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 luminari. Designed by luminari.

Type above and press Enter to search. Press Esc to cancel.