Firefox Blocks Flash By Default To Protect Against Fresh ‘Critical’ Vulnerabilities

Firefox now blocks Adobe Flash by default following the discovery of yet more zero-day vulnerabilities in the browser plug-in.

Two ‘critical’ flaws (CVE-2015-5122 and CVE-2015-5123) have been uncovered in files retrieved during the attack on controversial surveillance tools developer Hacking Team and have yet to be patched by Adobe, which expects to make updates available later this week.

Mark Schmidt, head of Firefox support at Mozilla, announced on Twitter that all versions of Flash were now blocked by the browser until a fix is made available.

Firefox Flash block

Occupy Flash“BIG NEWS!! All versions of Flash are blocked by default in Firefox as of now,” he said in a Tweet accompanied by an ‘occupy Flash’ image (left). “To be clear, Flash is only blocked until Adobe releases a version which isn’t being actively exploited by publicly known vulnerabilities.”

Mozilla says it routinely blocks add-ons, plugins, or other third-party software that “seriously compromises Firefox security, stability, or performance” when it becomes aware of them. Its block relates specifically to CVE-2015-5122.

Security firm TrendMicro says that at present the vulnerability is just a ‘proof of concept’ and has yet to see it exploited in the wild. If exploited, an attacker could engineer a crash and take control of the affected system.

Adobe’s promised fixes will be the 37th and 38th for the month of July so far, with an update last week fixing 36 flaws, including another vulnerability (CVE-2015-5119) discovered in 400GB worth of internal Hacking Team documents.

Are you a security pro? Try our quiz!

Steve McCaskill

Steve McCaskill is editor of TechWeekEurope and ChannelBiz. He joined as a reporter in 2011 and covers all areas of IT, with a particular interest in telecommunications, mobile and networking, along with sports technology.

View Comments

  • I have to admit when I first read about this, one of the first things that comes to mind is a couple of years back when Steve Jobs wrote a "rant" about the many downsides of Flash and how it's time to move on. Hopefully this gets resolved quickly.

Recent Posts

TSMC Denies Talks With Intel Over Chipmaking Joint Venture

Denial from TSMC, after multiple reports it was in talks with Intel over a joint…

16 hours ago

Apple iPhone Shipments In China Slide, As Cook Talks With Trump Official

CEO Tim Cook talks to Trump official, as IDC notes China's smartphone market growth, and…

18 hours ago

AMD Warns Of $800m Charge From US Chip Restrictions On China

Another big name chip maker expects a hefty financial charge, after the US tightened rules…

19 hours ago

Google Digital Ad Network Ruled Illegal Monopoly By Judge

More bad news for Google. Second time in less than a year that some part…

2 days ago

US State Dept Closes Office Flagging Russia, China Disinformation

Federal office that tackled misinformation and disinformation from hostile nations is closed down, after criticism…

2 days ago

Nvidia CEO Jensen Huang Makes Surprise Visit To China

After Nvidia admits it will take $5.5 billion charge as Trump export limits of slower…

2 days ago