Mozilla Issues New Firefox GPG Key Following Exposure

https://www.securityweek.com/wp-content/uploads/2024/10/Firefox.jpeg

Mozilla announced on Monday that it has issued a new GPG signing subkey used for some Firefox and Thunderbird artifacts after the previous key was accidentally exposed in a GitHub repository.

In general, if a GPG private signing key used for software releases is exposed, an attacker who obtains it could create valid signatures on malicious files.

This creates a supply chain attack risk: the attacker could distribute modified or malicious versions of the software that appear authentic. Successful exploitation would still require a way to deliver the signed files to users, for instance via a compromised mirror, an alternate download path, or social engineering.

However, in Mozilla’s case, the potential impact is mitigated by several factors.

The exposed GPG key was used to sign Firefox and Thunderbird artifacts such as Linux tarballs, RPM packages, and checksum files. An unencrypted copy of the key was inadvertently committed to a GitHub...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more