Firefox Blocks Flash By Default To Protect Against Fresh ‘Critical’ Vulnerabilities

Firefox now blocks Adobe Flash by default following the discovery of yet more zero-day vulnerabilities in the browser plug-in.

Two ‘critical’ flaws (CVE-2015-5122 and CVE-2015-5123) have been uncovered in files retrieved during the attack on controversial surveillance tools developer Hacking Team and have yet to be patched by Adobe, which expects to make updates available later this week.

Mark Schmidt, head of Firefox support at Mozilla, announced on Twitter that all versions of Flash were now blocked by the browser until a fix is made available.

Firefox Flash block

“BIG NEWS!! All versions of Flash are blocked by default in Firefox as of now,” he said in a Tweet accompanied by an ‘occupy Flash’ image (left). “To be clear, Flash is only blocked until Adobe releases a version which isn’t being actively exploited by publicly known vulnerabilities.”

Mozilla says it routinely blocks add-ons, plugins, or other third-party software that “seriously compromises Firefox security, stability, or performance” when it becomes aware of them. Its block relates specifically to CVE-2015-5122.

Security firm TrendMicro says that at present the vulnerability is just a ‘proof of concept’ and has yet to see it exploited in the wild. If exploited, an attacker could engineer a crash and take control of the affected system.

Adobe’s promised fixes will be the 37th and 38th for the month of July so far, with an update last week fixing 36 flaws, including another vulnerability (CVE-2015-5119) discovered in 400GB worth of internal Hacking Team documents.

Are you a security pro? Try our quiz!

Steve McCaskill

Steve McCaskill is editor of TechWeekEurope and ChannelBiz. He joined as a reporter in 2011 and covers all areas of IT, with a particular interest in telecommunications, mobile and networking, along with sports technology.

View Comments

  • I have to admit when I first read about this, one of the first things that comes to mind is a couple of years back when Steve Jobs wrote a "rant" about the many downsides of Flash and how it's time to move on. Hopefully this gets resolved quickly.

Recent Posts

Russia Accused Of Cyberattack On Germany’s Ruling Party, Defence Firms

German foreign minister warns Russia will face consequences for “absolutely intolerable” cyberattack on ruling party,…

2 days ago

Alphabet Axes Hundreds Of Staff From ‘Core’ Organisation

Google is reportedly laying off at least 200 staff from its “Core” organisation, including key…

2 days ago

Apple Announces Record Share Buyback, Amid iPhone Sales Decline

Investor appeasement? Apple unveils huge $110 billion share buyback program, as sales of iPhone decline…

2 days ago

Tesla Backs Away From Gigacasting Manufacturing – Report

Tesla retreats from pioneering gigacasting manufacturing process, amid cost cutting and challenges at EV giant

3 days ago

US Urges No AI Control Of Nuclear Weapons

No skynet please. After the US, UK and France pledge human only control of nuclear…

3 days ago