Firefox 3.5 was released last month with plenty of fanfare, but already Mozilla has had to issue a warning of a critical JavaScript flaw in the new browser.
The problem lies in the just-in-time (JIT) component of the JavaScript tool, and an exploit could let an attacker remotely execute code on the system – and a working exploit has been released. JIT is part of TraceMonkey, which was added for this release of the browser.
Although no patch has yet been developed, Mozilla says users can work around the problem by disabling the Firefox 3.5 JIT compiler, although this will reduce JavaScript performance.
The US Computer Emergency Response Team has suggested people completely disable JavaScript functionality in Firefox 3.5.