CVE-2024-9680: Mozilla Firefox Use-After-Free Vulnerability
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild.
Other sources
Firefox 128.3.1 ESR Chemspill, scheduled to drop TBA
Planning: - A 131.0.2 Desktop and Mobile dot release - A 115.16.1esr dot release and a 128.3.1esr release - Patch landed in beta for 132.0b5 which will be released Wednesday 10-09 as scheduled
— Red Hat
Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 131.0.3-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 128.3.1esr-1~deb11u1Fixed in 128.3.1esr-1~deb12u1Fixed in 128.3.1esr-2 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.16.0esr-1~deb11u1Fixed in 1:115.16.0esr-1~deb12u1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 115.16 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 128.3.1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 131.0.1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 131.0.2 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.16.1 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 128.3.1 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 131.0.2 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 128.3.1 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 115.16.1esr - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 131.0.1 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 128.3.1 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 115.16.0
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-9680?
CVE-2024-9680 is considered a critical vulnerability due to its potential for code execution exploits.
How do I fix CVE-2024-9680?
To fix CVE-2024-9680, update your Mozilla Firefox or Thunderbird to the latest versions recommended by Mozilla.
What type of vulnerability is CVE-2024-9680?
CVE-2024-9680 is a use-after-free vulnerability that can allow attackers to execute arbitrary code.
Which software versions are affected by CVE-2024-9680?
CVE-2024-9680 affects multiple versions of Mozilla Firefox and Thunderbird, prior to the latest security releases.
Is CVE-2024-9680 actively exploited?
Yes, there have been reports of CVE-2024-9680 being actively exploited in the wild.