CRITICAL

CVE-2024-9680

Mozilla Firefox 2024-10-09 CVSS v3.1
CVSS
9.8
KEV

Description

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.

Summary dbcve.org

A use-after-free vulnerability in Firefox and Thunderbird's Animation timelines component allows attackers to achieve arbitrary code execution in the content process. This memory corruption flaw has been confirmed as actively exploited in the wild, enabling remote attackers to potentially compromise affected systems through malicious web content.

Mitigation

Immediately update affected installations to Firefox 131.0.2+ (or ESR 128.3.1+/115.16.1+) and Thunderbird 131.0.1+ (or 128.3.1+/115.16.0+) to remediate this critical vulnerability.

Patch Commit

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

23.18%
Probability of exploitation in next 30 days
97.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE