Wednesday, June 1, 2022
HomeInformation SecurityFirefox 101 is out, this time with no 0-day scares (however replace...

Firefox 101 is out, this time with no 0-day scares (however replace anyway!) – Bare Safety


The newest scheduled Firefox replace is out, bringing the favored different browser to model 101.0.

This follows an intriguing month of Firefox 100 releases, with Firefox 100.0 arriving, as did Chromium 100 a month or so earlier than it, with none bother brought on by the shift from a two-digit to a three-digit model quantity.

Early in 2022, as each Chromium and Firefox co-incidentally approached their centuries at about the identical time, it appeared as if not less than just a few mainstream web sites have been extracting model numbers for each merchandise incorrectly.

Some websites, it appeared, have been looking out the browsers’ Consumer-Agent textual content strings for patterns that have been hard-wired to extract simply two digits’ price of model info.

As you possibly can think about, folding three digits into two offers you an error a bit just like the millennium bug, with 100 turning both into 10 or into 00, relying on which finish you prune.

Each 0 and 10 symbolize model numbers from a time gone, thus incorrectly flagging a brand-new browser as a recklessly outdated one, which some websites refused to simply accept.

Daimler’s web site after we visited with a pre-release of Edge 100 (Chromium-based) again in February 2022.
Satirically, after all, our browser was forward of the curve, not manner behind it.

Little doubt partly because of the efforts of each Google’s Chromium and Mozilla’s Firefox coders (who mixed to establish ill-behaved web sites, and even ready emergency “escape mechanisms” whereby their respesective browsers would proceed calling themselves 99.one thing when visiting ill-programmed net servers), the 100.0 launch of each browsers was finally uneventful…

…however Firefox adopted its common 100.0 launch with an emergency 100.0.1 launch, which turned on a model new Home windows safety characteristic that hadn’t fairly made the minimize in 100.0.

We puzzled why this new characteristic, which had been a very long time within the brewing and wasn’t designed to repair a selected, known-to-be-exploitable safety vulnerability, hadn’t merely been saved up and launch as a brand new characteristic within the scheduled 101.0 model.

However the truth that it was simply a few days earlier than the infamous Pwn2Own hacking competitors, the place contestants are introduced with bang-up-to-date computer systems on which to attempt their assaults, led us to imagine (or not less than to guess) that Mozilla figured that it was price getting out an official launch with further anti-hacking safety, simply in case.

Finally, nevertheless, Firefox was hacked, in a gloriously well-prepared double-exploit assault that took simply seven seconds to interrupt into the browser after which break again out of its protecting shell for a full sandbox escape.

To its credit score, Mozilla then launched 100.0.2 inside 48 hours, with fixes for each of those newly-disclosed bugs.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments