« Spotted
here, a lot of non tech and tech details about a recent combo of Firefox and Windows Zero Day.
User were helpless as soon as they connected to a malicious website.
For the Firefox part, I wonder if moving fully the JavaScript engine to Rust could help avoiding issues like this Use After Free.
For the Windows part, it explains how the Firefox sandbox could be escaped.
But the good part is: they released a patch in
25 hours, very close to their best during pwn2own in 21 hours. »