MacMusic  |  PcMusic  |  440 Software  |  440 Forums  |  440TV  |  Zicos
firefox
Recherche

Hardening the Firefox frontend

mercredi 9 avril 2025, 20:00 , par LWN.net
Tom Schuster, Frederik Braun, and Christoph Kerschbaumer have
published an article
on the Firefox Security team's Attack & Defense
blog that explains recent work to harden Firefox's frontend code.

We have rewritten over 600 JavaScript event handlers to mitigate XSS
and other injection attacks in the main Firefox user interface. This
mitigation will ship in Firefox 138. However, blocking the execution
of scripts in the parent process is not the end - we will expand this
technique to other contexts in the near future. There is still more
work to do as the UI requires JavaScript APIs with a high level of
privileges. However: We still eliminated a whole class of attacks,
significantly raising the bar for attackers to exploit Firefox.
https://lwn.net/Articles/1016978/

Voir aussi

News copyright owned by their original publishers | Copyright © 2004 - 2025 Zicos / 440Network
Date Actuelle
ven. 18 avril - 12:36 CEST