Firefox is opensource, or was before it went commercial. The code for firefox is widely known and plugins are written for it all the time. It would be really easy for someone to change the version to 4.8 and load it with spyware, which is what has been done..
I use the Linux version and it too is at 4.01