Executive brief
A use-after-free vulnerability in Animation timelines within Mozilla Firefox and Thunderbird allows a remote attacker to achieve arbitrary code execution in the content process. This vulnerability has been reported as being exploited in the wild.
Affected products
- Mozilla Firefox < 131.0.2
- Mozilla Firefox ESR < 128.3.1
- Mozilla Firefox ESR < 115.16.1
- Mozilla Thunderbird < 131.0.1
- Mozilla Thunderbird < 128.3.1
- Mozilla Thunderbird < 115.16.0
Timeline
- 2024-10-15: disclosed
- 2024-10-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-10-15: advisory: Mozilla published security advisories MFSA2024-51 and MFSA2024-52