No patch is available for this issue yet. Mitigations include using a browser such as Chrome that has mitigations in place to prevent exploitation. Ignoring the political side of the disclosure argument – it’s hard to decide what to do with a bug when it’s being exploited in the wild – however notifying users to at least temporarily change behavior is probably the safer bet here.