fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

10K
active users

As with any other app, we flagged Fennec and Mull with KnownVuln until the app is updated. Contributors fixed the issues that delayed versions 130 and later. Stand by for the build.

@fdroidorg The UX is a bit weird. Recommends to uninstall Fennec immediately due to a vulnerability, but doesn't have a link to/explanation of the vulnerability as far as I can tell.

@met @fdroidorg vulnerabilities in browsers are found somewhat recently, but they are usually patched quick enough to not be a big problem

However, Fennec is still on version 129 on F-Droid, while Firefox already got version 131, so the vulnerabilities found in 129 have been there for longer and therefore more easily exploitable

The specific vulnerabilities existing in Fennec should be mentioned in firefox 130's patch, as far as I know

met

@hi_im_sorro @fdroidorg Web browsers almost always have some vulnerabilities it seems, with every update removing some and introducing new ones. Anyways, "the app should be uninstalled immediately" suggests it's a very exploitable set of vulnerabilities, so it would be nice for F-Droid users to be informed of/referred to the specifics without needing to scour the internet for more information. (I understand F-Droid is a volunteer project, so not blaming anyone for this, more of a suggestion.)