Executive brief
A use-after-free vulnerability in SVG Animation allows for remote code execution. The flaw was actively exploited in the wild against Windows users of Firefox and Tor Browser to deanonymize users.
Affected products
- Mozilla Firefox < 50.0.2
- Mozilla Firefox ESR < 45.5.1
- Mozilla Thunderbird < 45.5.1
- Tor Project Tor Browser
Timeline
- 2016-11-30: advisory: Mozilla Foundation Security Advisory MFSA2016-92 published
- 2016-11-30: exploited: Exploit discovered in the wild targeting Tor Browser users
- 2023-06-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog