We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
80,259 News Articles

The 'unpatchable' flaw in Firefox

JavaScript handling error poses big problem

Two hackers over the weekend disclosed an 'unpatchable' security flaw in the Firefox browser, possibly giving out enough information for attackers to replicate the bug, according to a report.

Mischa Spiegelmock and Andrew Wbeelsoi made the presentation, called 'Lovin the LOLs, LOL is my will', at the ToorCon hacker conference in San Diego on Saturday. They said Firefox's implementation of JavaScript is responsible for the flaw, which they called "a complete mess", according to a report from industry journal ZDNet.

The bug affects Firefox on Windows, Mac OS X and Linux, and means that attackers could compromise a system simply by adding particular JavaScript code to a website, the hackers said. The exploit causes a stack overflow error, according to the report.

Spiegelmock and Wbeelsoi said Firefox's implementation of JavaScript would be "impossible to patch", according to the report. Mozilla acknowledged that the bug could be difficult to fix if it involves the JavaScript virtual machine.

The disclosure follows several days of security difficulties for Microsoft's IE (Internet Explorer) browser. Last week Microsoft issued an emergency patch for IE after attackers began exploiting an unpatched security flaw on thousands of websites. The bug was used to plant a wide variety of malicious programs on users' systems.

Last month Symantec published a report showing that Firefox had acknowledged more security holes than IE. However, Symantec said Mozilla is typically much more prompt at acknowledging holes when they're reported, and is capable of patching more quickly, because of its open-source nature.

IDG UK Sites

Best camera phone of 2015: iPhone 6 Plus vs LG G4 vs Galaxy S6 vs One M9 vs Nexus 6

IDG UK Sites

In defence of BlackBerrys

IDG UK Sites

Why we should reserve judgement on Apple ditching Helvetica in OS X/iOS for the Apple Watch's San...

IDG UK Sites

Retina 3.3GHz iMac 27in preview: Apple cuts £400 of price of Retina iMac with new model