CVE-2024-9392: Critical severity thunderbird vulnerability
A compromised content process could have allowed for the arbitrary loading of cross-origin pages.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-9392?
CVE-2024-9392 is considered to be a high severity vulnerability due to the potential for arbitrary loading of cross-origin pages.
How do I fix CVE-2024-9392?
To remediate CVE-2024-9392, users should update to Firefox version 131 or later, or to Firefox ESR version 128.3 or later.
Which software versions are affected by CVE-2024-9392?
CVE-2024-9392 affects Firefox versions prior to 131, Firefox ESR versions prior to 128.3, and Thunderbird versions prior to 131.
What could an attacker achieve by exploiting CVE-2024-9392?
An attacker exploiting CVE-2024-9392 could potentially load arbitrary cross-origin pages, compromising user privacy and security.
Is CVE-2024-9392 present in the latest Thunderbird version?
No, the latest versions of Thunderbird that are 131 or above are not vulnerable to CVE-2024-9392.