Mozilla delivers silent updating with Firefox 12 release

24.04.2012
Mozilla today released Firefox 12, patching 14 security bugs in the browser and moving it one step closer to matching rival Chrome in silent updating.

The latest in the line of updates that have rolled off the Mozilla development line every six weeks since mid-2011, Firefox 12 fixed seven vulnerabilities labeled "critical," the highest threat ranking in Mozilla's four-step scoring, four bugs tagged "high" and three pegged "moderate."

Mozilla also patched 19 other bugs, all critical, in the mobile edition of Firefox, which runs on the Android platform.

Among the 14 desktop vulnerabilities, Mozilla patched three that could be used by hackers in cross-site scripting (XSS) attacks, one that applied only to Windows Vista and Windows 7 PCs with hardware acceleration disabled and another in image rendering done by the WebGL 3D standard.

Two of the bugs were reported by security researchers at rivals Google and Opera Software. The Google engineer also notified Mozilla of all 19 vulnerabilities in the FreeType library that affected the mobile version of the browser.

Unlike Google, Mozilla does not call out bounties it's paid to outside researchers for reporting vulnerabilities, even though Mozilla does have a reward program.