Mozilla issued an urgent Firefox update to fix actively exploited flaw
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-29943 +1 in the same advisory: …29944 | An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1. NVD description · AI analysis pending | 9.8 group max | 23% |
| — | ||
| CVE-2024-9680 | Use-After-Free in Mozilla Firefox Animation Timelines Allows Code Execution Mozilla Firefox and Firefox ESR contain a use-after-free (CWE-416) in the browser's animation timelines component, which CISA describes as allowing code execution in the content process. The flaw is reachable through malicious web content: a crafted page can manipulate animation timelines so that an in-use object is freed, producing exploitable memory corruption. A successful attacker gains code execution in the content process, the sandboxed process that renders web pages, on the machine of the user who loaded the content. All users of Firefox and Firefox ESR are affected by the flaw itself. It is being actively exploited: the vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-10-15 with known ransomware use, and EPSS assigns it a 23.2% probability of exploitation in the next 30 days (98th percentile). Do: Apply Mozilla's patched Firefox/Firefox ESR release immediately and verify the running version via the browser's About Firefox dialog, since many installs only pick up auto-updates after a restart (per CISA's required action: apply mitigations per vendor instructions or discontinue use). Given the known ransomware use, prioritize enterprise ESR rollout and check for managed-update failures, auto-update-disabled installs, or unmanaged Firefox copies on user machines. Note that no public proof-of-concept is known, but KEV listing confirms exploitation, so patching should not wait for PoC availability. | 9.8 | 23% | KEV ransomware |
| masshundreds of millions of users (Firefox's global desktop user base of roughly 150-200M active users, plus enterprise Firefox ESR deployments) |
Full article240 words · extracted from securityaffairs.com · click to collapse

Mozilla released an urgent Firefox update to fix a critical use-after-free vulnerability actively exploited in ongoing attacks.
Mozilla released an emergency security update for its Firefox browser to address a critical use-after-free vulnerability, tracked as CVE-2024-9680, that is actively exploited in attacks.
The vulnerability CVE-2024-9680 resides in Animation timelines. Firefox Animation Timelines is a feature in the Firefox Developer Tools suite that allows developers to inspect, edit, and debug animations directly within the browser. It provides a visual interface for managing animations, including CSS animations and transitions, as well as those created with the Web Animations API.
An attacker could exploit this vulnerability to achieve code execution in the content process.
“An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines.” reads the advisory. “We have had reports of this vulnerability being exploited in the wild.”
The vulnerability was discovered by the security researcher Damien Schaeffer from ESET.
The vulnerability impacts Firefox 131.0.2, Firefox ESR 128.3.1, and Firefox ESR 115.16.1. Mozilla addressed the flaw with the release of Firefox 131.0.2, Firefox ESR 115.16.1, and Firefox ESR 128.3.1.
Experts urge users to upgrade to the latest version as soon as possible.
In March, Mozilla addressed two Firefox zero-day vulnerabilities, respectively tracked as CVE-2024-29944 and CVE-2024-29943, which were exploited during the Pwn2Own Vancouver 2024 hacking competition.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Mozilla)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/169590/security/mozilla-firefox-actively-exploited-flaw.html