skip to Main Content
bitcoin
Bitcoin (BTC) $ 76,221.42 0.44%
vested-xor
Vested XOR (VXOR) $ 3,405.08 99,999.99%
ethereum
Ethereum (ETH) $ 2,900.05 7.78%
tether
Tether (USDT) $ 1.00 0.09%
solana
Solana (SOL) $ 197.03 3.99%
bnb
BNB (BNB) $ 601.69 1.97%
usd-coin
USDC (USDC) $ 1.00 0.03%
xrp
XRP (XRP) $ 0.557249 2.54%
dogecoin
Dogecoin (DOGE) $ 0.194405 0.94%
staked-ether
Lido Staked Ether (STETH) $ 2,900.48 7.81%

Mozilla Closes Holes That Led to Coinbase Hacks


news

A pair of simple Mozilla vulnerabilities made it easier for hackers to phish Coinbase employees. The exploit, detailed by ZDNet, was a remote code execution attack that could force machines running Firefox to install spyware to capture passwords and other data.

The two vulnerabilities – CVE-2019-11708 and CVE-2019-11707 – first appeared in April 15 and hackers used them to spear-phish Coinbase employees. When they visited sites linked in the email the browser would download a piece of spyware to steal logins and other data.

Some detail from the exploit suggests that the bug could escalate privileges outside of the “sandbox” where most Mozilla code runs:

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user’s computer.

The two vulnerabilities combined to create a perfect storm, allowing hackers to run malware installers instantly. Researchers discovered the exploits on April 15 and they suspect that hackers saw them in Mozilla’s Bugzilla bug tracking database and exploited them before they could be patched. The hack did not effect Coinbase users.

Mozilla is asking users to update their browsers in order close these holes.

Image via Shutterstock.

Loading data ...
Comparison
View chart compare
View table compare
Back To Top