CVE-2024-9680
Description
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.
Summary dbcve.org
A use-after-free vulnerability in Firefox and Thunderbird's Animation timelines component allows attackers to achieve arbitrary code execution in the content process. This memory corruption flaw has been confirmed as actively exploited in the wild, enabling remote attackers to potentially compromise affected systems through malicious web content.
Mitigation
Immediately update affected installations to Firefox 131.0.2+ (or ESR 128.3.1+/115.16.1+) and Thunderbird 131.0.1+ (or 128.3.1+/115.16.0+) to remediate this critical vulnerability.