xiota [1] filed a deletion request for mercury-browser-avx2-bin [2]:

This package should be deleted to protect potential users from
unpatched vulnerability CVE-2024-9680, which allows unwanted code
execution.

The critical security vulnerability was announced and fixed in Firefox
nearly three months ago.  There have been "reports of this
vulnerability being exploited in the wild."

Mercury browser developers were notified, but have neglected to
address the issue.  Given the nature of the problem, the project
should be considered discontinued / unmaintained, and this package
deleted.

[1] https://aur.archlinux.org/account/xiota/
[2] https://aur.archlinux.org/pkgbase/mercury-browser-avx2-bin/

Reply via email to