A zero-day vulnerability in Firefox has been actively abused by cybercriminals. The vulnerability allowed them to search for sensitive files on the affected system and upload them to a server. Mozilla released an emergency patch last night to fix the issue.

The attack was discovered in the wild on a Russian news site. The exploit caused files to be uploaded to a server in the Ukraine. The attackers targeted mainly files used by developers such as configuration files of a FTP clients and version tracking software. The attack targeted both Linux and Windows users. For some reason Mac users weren't part of the attack while the vulnerability was also exploitable on that operating system.
Mozilla advises Firefox users on Windows and Linux that use mentioned software to change their passwords. The company stresses that although the attack has been discovered on a Russian website, other websites might also be attacked. Firefox users with an Adblock extension are possible protected against the exploit but it depends on what kind of filter they use. The exploits appear to be distributed through advertisements.
The vulnerability is part of the mechanism that separates Javascript from the PDF Viewer in Firefox. Therefore the vulnerability is not in the Android version of the browser which doesn't use an embedded PDF viewer. An attacker can't execute random code through the exploit to install malware or take over the computer, it can only 'steal' files.
Mozilla has marked the vulnerability as critical and advises users to update immediately.















