firefox2 articles
77 Firefox Add-ons Caught Running a Coordinated Crypto Wallet Heist
Forty malicious Firefox extensions have been discovered impersonating legitimate Web3 products like OKX and Rabby Wallet as part of a campaign called "Offside Wallet Theft Factory," believed to have been active since March 2026. The extensions steal cryptocurrency wallet secrets — including recovery phrases and private keys — using methods such as fake wallet pages, hidden malicious code, and exfiltration via Cloudflare Workers and Supabase. Some extensions initially appeared as innocent sports score or utility tools before being repurposed as wallet-stealing malware, with researchers noting that the low cost of repeatedly publishing disposable extensions makes the campaign highly scalable and persistent.
One Webpage Visit Was Enough to Own Your Browser — and Then Your Kernel
Researchers at Nebula Security have disclosed a patched Firefox vulnerability (CVE-2026-10702) that allowed arbitrary code execution simply by visiting a malicious webpage, with no additional user interaction required. The flaw, stemming from a JIT compiler error that incorrectly treated a memory-mutating operation as a safe read, affected Firefox versions 147 through 151.0.2 and also impacted Tor Browser builds using vulnerable Firefox versions. Nebula chained the browser exploit with a separate Linux kernel flaw (CVE-2026-43499) to achieve full device compromise on ARM64 Android devices, though updating to Firefox 151.0.3 blocks the browser entry point.