Alex313031 / Mercury

Firefox fork with compiler optimizations and patches from Librewolf, Waterfox, and GNU IceCat.
https://thorium.rocks/mercury
Mozilla Public License 2.0
1.16k stars 24 forks source link

Firefox Zero-day (CVE-2024-9680) #227

Open ThatBigDerp opened 4 hours ago

ThatBigDerp commented 4 hours ago

Recently Firefox patched the CVE-2024-9680 zero-day in the following versions:

Currently Mercury is based on Firefox 192.0.02 which means it's vulnerable. My suggestion is due to low update activity to switch to Firefox's ESR release due to their slower, but more stable release cycle also reducing the need for you to update Mercury, if not at least update the browser to the latest Firefox version with the vulnerabilities patched, because according to Mozilla the vulnerability is already being exploited.

gz83 commented 3 hours ago

We will update as quickly as possible, but the disclosed vulnerabilities do not immediately put your device at risk.