Mozilla Patches Two Zero-Day Vulnerabilities in Firefox Used to Install Backdoors on Macs, Update Now - MacRumors
Skip to Content

Mozilla Patches Two Zero-Day Vulnerabilities in Firefox Used to Install Backdoors on Macs, Update Now

by

Mozilla has patched two zero-day security vulnerabilities in Firefox that allowed backdoors to be installed on Macs, bypassing Apple's usual XProtect and Gatekeeper protections. Firefox users should update the browser immediately.

firefox quantum
Ars Technica's Dan Goodin:

Mozilla released an update on Tuesday that fixed a code-execution vulnerability in a JavaScript programming method known as Array.pop. On Thursday, Mozilla issued a second patch fixing a privilege-escalation flaw that allowed code to break out of a security sandbox that Firefox uses to prevent untrusted content from interacting with sensitive parts of a computer operating system.

The zero-days were exploited by unnamed hackers this week, but so far, attacks are known only to have targeted Mac users involved in cryptocurrency.


As noted by Mac security expert Patrick Wardle, XProtect and Gatekeeper provided no protection in this case, as they only scan applications that have a quarantine flag set. Fortunately, this may change in macOS Catalina.

Firefox users on Mac should update the web browser to version 67.0.4 as soon as possible to keep themselves protected.

More details can be read at Ars Technica.

Top Rated Comments

___joshuaturner Avatar
90 months ago
Why does this article of rather large importance get stuck in the sidebar blog while articles about Google not making tablets anymore are in the main feed for everyone to see?
Score: 18 Votes (Like | Disagree)
Morod Avatar
90 months ago
THANKS!
Score: 4 Votes (Like | Disagree)
Secondempire Avatar
90 months ago
And if you're using Tor Browser, don't forget to update it to version 8.5.3 (it's based on Firefox)
Score: 3 Votes (Like | Disagree)
90 months ago
I updated yesterday, but still don't use Firefox as my main browser. I am impressed by how much that browser has improved in terms of its elegance and design. It used to feel foreign on the Mac, but now it feels much more native.
Score: 3 Votes (Like | Disagree)
JosephAW Avatar
90 months ago
Official support goes all the way back to Mavericks, what are you running that you can't update?
Mac Pro 1,1. Snow Leopard. :p
Last official macOS is 10.7. Yeah yeah I know you can replace boot file with pikers file but I'd rather run an official OS from Apple. Oh course Windows X 64 bit runs fine.
Score: 2 Votes (Like | Disagree)
thisisnotmyname Avatar
90 months ago
What about macOS version that can't support FF 67? Any ESR updates or does this only effect modern engine?
Official support goes all the way back to Mavericks, what are you running that you can't update?
Score: 2 Votes (Like | Disagree)

Popular Stories

M5 Vision Pro Thumb 2

Apple Has Given Up on the Vision Pro After M5 Refresh Flop

Wednesday April 29, 2026 11:31 am PDT by
Apple has all but given up on the Vision Pro after the M5 model failed to revitalize interest in the device, MacRumors has learned. Apple updated the Vision Pro with a faster M5 chip and a more comfortable band in October 2025, but there were no other hardware changes, and consumers still weren't interested. The Vision Pro has been criticized for its high price tag and its uncomfortable...
Four iPhone 18 Pro Colors Mock Feature

iPhone 18 Pro to Launch in September With These 10 New Features

Tuesday April 28, 2026 9:35 am PDT by
While the iPhone 18 Pro and iPhone 18 Pro Max are not launching until September, there are already plenty of rumors about the devices. It was initially reported that the iPhone 18 Pro models would have fully under-screen Face ID, with only a front camera visible in the top-left corner of the screen. However, the latest rumors indicate that only one Face ID component will be moved under the...
iphone 17e magsafe

Apple Reportedly Questioning Whether iPhone Should Drop MagSafe

Wednesday April 29, 2026 8:26 am PDT by
A leaker claims Apple is currently embroiled in an internal debate over whether MagSafe should remain a standard iPhone feature. The Weibo leaker known as "Instant Digital" says that when MagSafe was first introduced, the mood inside Apple was reportedly aggressive about its expansion. MagSafe for the iPhone was introduced with the iPhone 12 lineup in 2020, bringing a ring of magnets to the...