After researcher Gerry Eisenhaur reported about Firefox flaw about information leaks that can allow an attacker to load any javascript file on a machine, Mozilla announced that the vulnerability will be patched with Firefox 2.0.0.12. New patch is expected shortly. As Mozilla official Snyder says Firefox is not vulnerable by default. attacker can use holes in add-ons to collect session information, including session cookies and session history. After Firefox patch also new patched versions of vulnerable add-ons are expected.