• News/
  • https://www.bleepingcomputer.com/news/security/mozilla-fixes-two-firefox-zero-day-bugs-exploited-at-pwn2own/

Mozilla fixes two Firefox zero-day bugs exploited at Pwn2Own

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 22, 2024
·
Updated

Mozilla has released security updates to fix two zero-day vulnerabilities in the Firefox web browser exploited during the Pwn2Own Vancouver 2024 hacking competition. Manfred Paul (@_manfp) earned a $100,000 award and 10 Master of Pwn points after exploiting an out-of-bounds (OOB) write flaw (CVE-2024-29943) to gain remote code execution and escaping Mozilla Firefox's sandbox using an exposed dangerous function weakness (CVE-2024-29944). Mozilla says the first vulnerability can let attackers access a JavaScript object out-of-bounds by exploiting range-based bounds check elimination on vulnerable systems. "An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination," Mozilla explained. The second one is described as a privileged JavaScript execution via event handlers that could enable an attacker to execute arbitrary code in the parent process of the Firefox Desktop web browser. Mozilla fixed the security flaws in Firefox 124.0.1 and Firefox ESR 115.9.1 to block potential remote code execution attacks targeting unpatched web browsers on desktop devices.

​The two security vulnerabilities were patched only one day after Manfred Paul exploited and reported them at the Pwn2Own hacking contest. However, after the Pwn2Own competition, vendors usually take their time to release patches as they have 90 days to push fixes until Trend Micro's Zero Day Initiative publicly discloses them. Pwn2Own 2024 Vancouver en...

Read full article

Affected Software

2 affected components
Mozilla Firefox=124.0.1
Mozilla Firefox ESR=115.9.1
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Mozilla's release of security updates to address two zero-day vulnerabilities in Firefox exploited at the Pwn2Own competition.

2

What security implications are discussed in the article?

The article highlights that the vulnerabilities could be actively exploited by attackers, emphasizing the importance of timely security updates.

3

What products or software are affected by the vulnerabilities?

The vulnerabilities affect Mozilla Firefox version 124.0.1 and Firefox ESR version 115.9.1.

4

Who discovered the vulnerabilities and received a reward?

The vulnerabilities were exploited by Manfred Paul, who earned a $100,000 reward at the Pwn2Own competition.

5

What should users do to protect themselves against these vulnerabilities?

Users should update their Firefox and Firefox ESR browsers to the latest versions to mitigate the risks associated with these zero-day vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203