ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Firefox Zero-Day Under Attack: Update Your Browser Immediately

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-9680

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-9680
Use-After-Free in Mozilla Firefox Animation Timelines Allows Code Execution

Mozilla Firefox and Firefox ESR contain a use-after-free (CWE-416) in the browser's animation timelines component, which CISA describes as allowing code execution in the content process. The flaw is reachable through malicious web content: a crafted page can manipulate animation timelines so that an in-use object is freed, producing exploitable memory corruption. A successful attacker gains code execution in the content process, the sandboxed process that renders web pages, on the machine of the user who loaded the content. All users of Firefox and Firefox ESR are affected by the flaw itself. It is being actively exploited: the vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-10-15 with known ransomware use, and EPSS assigns it a 23.2% probability of exploitation in the next 30 days (98th percentile).

Do: Apply Mozilla's patched Firefox/Firefox ESR release immediately and verify the running version via the browser's About Firefox dialog, since many installs only pick up auto-updates after a restart (per CISA's required action: apply mitigations per vendor instructions or discontinue use). Given the known ransomware use, prioritize enterprise ESR rollout and check for managed-update failures, auto-update-disabled installs, or unmanaged Firefox copies on user machines. Note that no public proof-of-concept is known, but KEV listing confirms exploitation, so patching should not wait for PoC availability.

9.823% KEV ransomware
  • Mozilla Firefox
  • Mozilla Firefox ESR
masshundreds of millions of users (Firefox's global desktop user base of roughly 150-200M active users, plus enterprise Firefox ESR deployments)
Full article338 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananOct 10, 2024Vulnerability / Browser Security

Mozilla has revealed that a critical security flaw impacting Firefox and Firefox Extended Support Release (ESR) has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2024-9680 (CVSS score: 9.8), has been described as a use-after-free bug in the Animation timeline component.

"An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines," Mozilla said in a Wednesday advisory.

"We have had reports of this vulnerability being exploited in the wild."

Security researcher Damien Schaeffer from Slovakian company ESET has been credited with discovering and reporting the vulnerability.

The issue has been addressed in the following versions of the web browser -

  • Firefox 131.0.2
  • Firefox ESR 128.3.1, and
  • Firefox ESR 115.16.1.

There are currently no details on how the vulnerability is being exploited in real-world attacks and the identity of the threat actors behind them.

That said, such remote code execution vulnerabilities could be weaponized in several ways, either as part of a watering hole attack targeting specific websites or by means of a drive-by download campaign that tricks users into visiting bogus websites.

Users are advised to update to the latest version to stay protected against active threats.

Update

The Tor project has released an emergency update to the Tor Browser (version 13.5.7) to address CVE-2024-9680, which has come under active exploitation in the wild.

"Using this vulnerability, an attacker could take control of Tor Browser, but probably not deanonymize you in Tails," it said. "Mozilla is aware of this attack being used in the wild against Tor Browser users."

Mozilla, in a separate post on October 11, 2024, said it was sent by ESET a sample containing a "full exploit chain that allowed remote code execution on a user's computer." It also revealed that the fix was shipped within 25 hours of responsible disclosure.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/10/mozilla-warns-of-active-exploitation-in.html