
As Firefox's market share increases, the Mozilla browser begins to share similitudes with Microsoft Internet Explorer. One aspect that recommended Firefox over IE was the increased security it
delivered. In this context, a larger market share is equivalent to a decrease in the security as Firefox is also increasing its target profile diverting some of the fire targeting Internet Explorer.
Mischa Spiegelmock and Andrew Wbeelsoi revealed in a presentation at the ToorCon hacker conference, that Firefox is vulnerable to attacks via malicious JavaScript code, because of the way the browser is built. The JavaScript management vulnerability extends over Firefox on Windows, Apple Computer's Mac OS X and Linux.
"Internet Explorer, everybody knows, is not very secure. But Firefox is also fairly insecure," stated Spiegelmock, adding that because of the extent of the implementation of JavScript code in Firefox, the vulnerability "is impossible to patch."
Window Snyder, Mozilla's security chief stated that the company will address the issue. "What they are describing might be a variation on an old attack," she commented. "We're going to do some investigating. It looks like they had enough information in their slide for an attacker to reproduce it. I think it is unfortunate because it puts users at risk, but that seems to be their goal. If it is in the JavaScript virtual machine, it is not going to be a quick fix."