Executive brief
A race condition in Mozilla Firefox and Thunderbird when handling a ReadableStream can lead to a use-after-free vulnerability. This flaw allows for unspecified impacts and has been observed in targeted attacks in the wild.
Affected products
- Mozilla Firefox < 74.0.1
- Mozilla Firefox ESR < 68.6.1
- Mozilla Thunderbird < 68.7.0
Timeline
- 2020-04-24: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild in CISA KEV catalog and vendor advisory.