Chipp.in Tech News and Reviews

Windows, Security & Privacy, Open Source and more

Menu
  • Home
  • Windows
  • Security & Privacy
  • Gaming
  • Guides
  • Windows 11 Book
  • Contact
  • RSS Feed
Menu
Firefox 124.0.1

Firefox 124.0.1 fixes two critical security issues

Posted on March 22, 2024March 22, 2024 by Martin Brinkmann

It has been just a few days since the release of Firefox 124.0, but here is Firefox 124.0.1 already. Usually, when this happens, it is either a security update or a bug fix update that address major issues.

It is a security update in the case of Firefox 124.0.1. The official release notes include just two words: “Security fixes”. The issue affects desktop versions of the web browser. It is unclear if the Android version is also affected. There is no release notes page for Firefox 124.0.1 for Android at the time of writing.

The security advisory page lists two security issues that Mozilla addressed in the Firefox update. Both have a severity rating of critical, which is the highest severity rating available:

  • CVE-2024-29943: Out-of-bounds access via Range Analysis bypass
  • CVE-2024-29944: Privileged JavaScript Execution via Event Handlers

Both security issues were reported to Mozilla by Manfred Paul via Trend Micro’s Zero Day initiative.

The first security issue could allow an attacker to “perform an out-of-bounds read or write” on JavaScript objects by “fooling range-based bounds check elimination”.

The second issue allows an attacker to “inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process”.

Without going into too many details on the issues, they’d allow an attacker to execute JavaScript code or control JavaScript objects in the Firefox web browser.

Mozilla does not reveal if the issues are exploited in the wild. It is a good idea to update Firefox Stable installations as soon as possible to protect the browser from potential attacks targeting the vulnerabilities.

Updating Firefox

The security update is available already. While most Firefox installations will get updated automatically, cautious Firefox users and system administrators may want to speed up the installation of the update.

Here is how this is done:

  1. Open the Firefox web browser.
  2. Select Menu > Help > About Firefox.
  3. Firefox displays the current version. It should pick up the update at the same time. In other words, it is downloaded and installed automatically.
  4. A restart of the browser is required to complete the process.

Repeat the steps above and you should see Firefox 124.0.1 listed as the version on the about page.

Firefox is also available on the Mozilla website. Click here to open the download page and download the latest version to the local system.

Tags: firefox
Category: Security & Privacy

Post navigation

← Brave 1.64 browser update brings more AI and blocks VPN services from installing by default
Windows 11: Lock Screen widgets in development →

3 thoughts on “Firefox 124.0.1 fixes two critical security issues”

  1. Tom Hawack says:
    March 22, 2024 at 6:58 pm

    When an unexpected upgrade is available chances are a user may miss them, especially if he hasn’t set his application to auto-update (such as myself).
    Again, Martin, your reactivity is most appreciated.
    We have upgraded Firefox 115.9.0 ESR to 115.9.1 ESR accordingly.

    Reply
  2. Service Pack says:
    March 23, 2024 at 4:39 am

    Firefox ESR 115.9.1 was also released

    Reply
  3. Paul(us) says:
    March 29, 2024 at 1:18 pm

    Second that! I like to mention that at the moment I like this new Chipp.in better than the good old Ghacks.net

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Support This Site

If you like what I do please support me!

Any tip is appreciated. Thanks!
  • February 20, 2026 by Martin Brinkmann Google teases three new Chrome features that sound familiar
  • February 19, 2026 by Martin Brinkmann No Login? No Problem: 5 Google Maps Alternatives That Respect Your Privacy
  • February 18, 2026 by Martin Brinkmann Mozilla ends support for Firefox on Windows 7 and 8/8.1
  • February 17, 2026 by Martin Brinkmann Chrome Stable Channel Update: Emergency Fix for Active CSS Exploit
  • February 16, 2026 by Martin Brinkmann YouTube is reportedly hiding video descriptions and comments for some adblock users

About

We talk, write and dream about Technology 24/7 here at Chipp.in. The site, created by Martin Brinkmann in 2023, focuses on well-researched tech news, reviews, guides, help and more.

Legal Notice

Our commitment

Many websites write about tech, but chipp.in is special in several ways. All of our guides are unique, and we will never just rehash news that you find elsewhere.

Read the About page for additional information on the site and its founder and author.

Support Us

We don't run advertisement on this site that tracks users. If you see ads, they are static links. Ads, including affiliate links, never affect our writing on this site.

Here is a link to our privacy policy

©2026 Chipp.in Tech News and Reviews