Junglewise Threat Intelligence

CVE-2024-9680: Mozilla Firefox Use-After-Free Vulnerability

CVE-2024-9680 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-10-15

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A use-after-free vulnerability in Animation timelines within Mozilla Firefox and Thunderbird allows a remote attacker to achieve arbitrary code execution in the content process. This vulnerability has been reported as being exploited in the wild.

Affected products

  • Mozilla Firefox < 131.0.2
  • Mozilla Firefox ESR < 128.3.1
  • Mozilla Firefox ESR < 115.16.1
  • Mozilla Thunderbird < 131.0.1
  • Mozilla Thunderbird < 128.3.1
  • Mozilla Thunderbird < 115.16.0

Timeline

  • 2024-10-15: disclosed
  • 2024-10-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-10-15: advisory: Mozilla published security advisories MFSA2024-51 and MFSA2024-52

Related threats