So I went to update my apps and was greeted with these warnings in FDroid. A quick and basic search online and in various communities yielded no news regarding a major compromise in Fennec and Mull, does anyone know more about this or have you seen any news regarding a vulnerability? Curious if this is a false positive or if there is something going on with firefox forks.

  • CrazyLikeGollum@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    18 days ago

    Mull at least has been fixed in the divestOS repo. I can’t speak to fennec as I don’t use it.

    The version in the f-droid main repo is behind because of Mozilla changing their repo system thus screwing with the build process and at least for now currently requiring a compiler that doesn’t meet F-Droid’s (IMO slightly ridiculous) standards for allowable software.

  • umami_wasabi@lemmy.ml
    link
    fedilink
    arrow-up
    1
    ·
    edit-2
    18 days ago

    It is the recent use after free vuln actively exploited found in FF, which both Fennec and Mull relies as upstream. This compounds on changes made to Android NDK and the source of FF move into the monorepo, making them harder to build. Hence, they’re still vulnerable to the attack.

    • youmaynotknow@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      18 days ago

      Or you can install directly from Divest via FFupdater, or from their github (I use Obtainium for that).