ACTIVELY EXPLOITED3 sources verified·1 min read
By Lyrie Threat Intelligence·3/3/2022
CVE-2013-1675 added to CISA KEV: Mozilla Firefox
Status: ✅ Confirmed exploited in the wild
Date added: 2022-03-03
Required action: Apply updates per vendor instructions.
Due date: 2022-03-24
Why this matters
Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
Sources
Lyrie Verdict
Lyrie's autonomous detection layer catches active exploitation primitives at machine speed — closing the gap between disclosure and weaponization that traditional defense simply can't cover.