So I went to update my apps and was greeted with these warnings in FDroid. A quick and basic search online and in various communities yielded no news regarding a major compromise in Fennec and Mull, does anyone know more about this or have you seen any news regarding a vulnerability? Curious if this is a false positive or if there is something going on with firefox forks.

It’s still waiting on a repackaging effort

https://gitlab.com/relan/fennecbuild/-/merge_requests/63

Looks like the latest hurdle is that Firefox is relying on some Google-specific variables being present, which fails on AOSP

Mull at least has been fixed in the divestOS repo. I can’t speak to fennec as I don’t use it.

The version in the f-droid main repo is behind because of Mozilla changing their repo system thus screwing with the build process and at least for now currently requiring a compiler that doesn’t meet F-Droid’s (IMO slightly ridiculous) standards for allowable software.

Thanks! Added their repo and reinstalled. Secure again. 😎

Mull from divestos repo works fine! Use FFupdater to install it or link the fdroid repo to your fdroid

slurp
link
fedilink
108M

Mull is fine if you use the divestos repo directly, but the f-droid version is behind

merde alors
link
fedilink
12
edit-2
8M

https://lemmy.ml/post/21783142

2 of the last 5 posts on !fdroid@lemmy.ml are on this

umami_wasabi
link
fedilink
30
edit-2
8M

It is the recent use after free vuln actively exploited found in FF, which both Fennec and Mull relies as upstream. This compounds on changes made to Android NDK and the source of FF move into the monorepo, making them harder to build. Hence, they’re still vulnerable to the attack.

found in Fx*

the source of Fx*

SomeLemmyUser
link
fedilink
7
edit-2
8M

Had the same, promptly uninstalled, didnt find infos.

deleted by creator

True, but the config settings should be good Form the get go, that’s the reason the app exitists after all and ublck and noscript are installed fast. But thanks for the tip :)

@paf@jlai.lu
link
fedilink
18M

Haven’t read so can’t tell you but you will find info at https://leminal.space/post/11699480

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 124 users / day
  • 1.05K users / week
  • 1.3K users / month
  • 4.58K users / 6 months
  • 1 subscriber
  • 3.87K Posts
  • 97.6K Comments
  • Modlog