Can I get more info on why these are showing up? I’ve never seen such a thing on F-Droid before.

  • DishonestBirb@lemmy.world
    link
    fedilink
    arrow-up
    3
    arrow-down
    1
    ·
    edit-2
    2 hours ago

    Uninstalling my primary browser isn’t really a practical solution, what am I supposed to use, Chrome? How about fixing the version they’re shipping? Or should I be looking somewhere other than F-Droid for Android Firefox?

    • cyberwolfie@lemmy.ml
      link
      fedilink
      arrow-up
      3
      ·
      edit-2
      1 hour ago

      I changed to the Divest-repo for Mull, and they have an updated version that has fixed these security issues.

      ETA: Different signing keys though, so you can’t just update it, but have to reinstall.

    • kazaika@lemmy.world
      link
      fedilink
      arrow-up
      3
      arrow-down
      1
      ·
      2 hours ago

      Theyre the distributor, the dont fix apps and its not their job to do so. Getting the same app from a different source wont change anything

      • Swedneck@discuss.tchncs.de
        link
        fedilink
        arrow-up
        2
        ·
        1 hour ago

        huh? no one’s asking them to fix firefox, we’re asking that they just ship the latest version.

        the warning states that several vulnerabilities have been fixed since firefox version 130, f-droid’s latest version of the package is 129: that very much makes it sound like the problem is wholly caused by f-droid not making version 130 available.

  • N4CHEM@lemmy.ml
    link
    fedilink
    arrow-up
    21
    ·
    edit-2
    9 hours ago

    There was a critical vulnerability found on Firefox some days ago: CVE-2024-9680. Fennec and Mull are forks of Firefox. They both fixed this issue already in their source code, BUT there is a problem preventing F-Droid from building these updated, fixed versions.

    In the case of Mull, you can download the updated version from the DivestOS F-Droid repository: https://divestos.org/fdroid/official/, but if you are currently using the F-Droid version you will need to uninstall it first, since they have different signatures.

    • SatyrSack@feddit.org
      link
      fedilink
      English
      arrow-up
      8
      ·
      15 hours ago

      The issue preventing updates should be resolved soon thanks to @linsui fixing it!

      What is wrong with updating?

      • WhyJiffie@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        12
        ·
        11 hours ago

        it was mentioned in a This Week In F-droid blog post around September. basically google fucked up an important development library, and any firefox forks (possibly some other apps too) could not be built anymore normally. of course google was unwilling to fix the issue, so linsui (and F-droid member) fixed the build process somehow, possibly temporarily.

        you may ask how is this not a problem for the official release of the firefox app, and my answer is that they probably build this component for themselves, and fixed the problem in house (if they had it at all)

        • SatyrSack@feddit.org
          link
          fedilink
          English
          arrow-up
          4
          arrow-down
          1
          ·
          9 hours ago

          Right, but that comment that I quoted from the F-Droid forum makes it sound like there is some sort of issue updating to a build with the vulnerability patched. My Mull is on 131.0.3, and I do not remember having an issue updating it.

          • N4CHEM@lemmy.ml
            link
            fedilink
            arrow-up
            6
            ·
            9 hours ago

            You’re probably getting your Mull updates via the DivestOS repository, not the official F-Droid repository.

  • Quintus@lemmy.ml
    link
    fedilink
    arrow-up
    20
    ·
    18 hours ago

    Are these two from the same maintainer? If not, considering that they both use Firefox Android as their base, does this mean there is a vulnerability in Firefox Android?

    • Piwix@lemm.ee
      link
      fedilink
      arrow-up
      33
      ·
      17 hours ago

      There was and it was fixed by the looks of it. Guessing these apps have not urgently pulled the fixes in and released an update, so F-droid is urging people not to use the apps until so

      • WhyJiffie@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        5
        ·
        11 hours ago

        they pulled the fixes, but couldn’t build because google fucked up the NDK. my other comment has more details

    • kitnaht@lemmy.world
      link
      fedilink
      arrow-up
      18
      ·
      edit-2
      17 hours ago

      Yes, there was a remote code execution vulnerability in the CSS engine of firefox a little while ago. If you’re on desktop version 131 or lower, update to 131.0.3 when possible. I don’t know how the versioning works for the Android versions here…

          • Redjard@lemmy.dbzer0.com
            link
            fedilink
            arrow-up
            7
            ·
            17 hours ago

            Yeah that seems about right.

            I don’t know how the versioning works for the Android versions here…

            Android has the same versions as desktop here, which is why there is no differentiation. The main chunk of firefox is platform independent (and even used in thunderbird too).

            So any firefox android app and fork thereof needs that version 131.0.3+ too (unless it is esr which is 128 currently).

  • GolfNovemberUniform@lemmy.ml
    link
    fedilink
    arrow-up
    7
    arrow-down
    1
    ·
    18 hours ago

    It doesn’t say anything like that in Droid-ify. I don’t remember any recent reports of vulnerabilities either.

  • Possibly linux@lemmy.zip
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    5
    ·
    edit-2
    13 hours ago

    Its a nice feature

    Many apps need security patches from time to time and web browsers tend to need the most security updates outside of the OS.

    As far as security goes please use a up to date browser. I would recommend using the official repo for each of those apps.