A Mozilla announced that Firefox browser users can now do the download version 88.1.3 update and thus fix a vulnerability in the security system. This bug, now detected and fixed, allowed an attacker to access your data through a JavaScript exploit.
The exploit is called a “universal cross-site scripting” vulnerability, or UXSS (Universal Cross-site Scripting) vulnerability. In practice, this means that attackers had a way to access your private browser data from website “X” while you were browsing website “Y.” To prevent issues like this, browsers should enforce what’s called a “same-origin policy.” With this, locally saved web data is blocked from being read later only by the same website that saved it.
The flaw, which according to the company only affected users of the Android operating system, circumvented this policy and allowed the attacker, through cookies, to view all data entered by users. This could then leave vulnerable including bank passwords, credit card passwords, and other personal and confidential information.
How to update?
Before the security update, the vulnerable exploit gave an attacker the ability to trick Firefox by altering the JavaScript code and transforming a fake page into a genuine one. This gave the user the false impression that they were in a protected environment, when in fact they were completely exposed.
Firefox security update is listed in Google Play Store as version 88.0.1 and, for some users, it is made available automatically. If it is not, you need to make the request manually. Just go to the list of updated apps and check which version is installed on your device. If it is not the one mentioned above, just click Update and download the latest one.
Through which channels you reach those people, classic and out of the box. Tom's Guide