Mozilla fixes critical Firefox bug exploited in the wild
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-9680 | Use-After-Free in Mozilla Firefox Animation Timelines Allows Code Execution Mozilla Firefox and Firefox ESR contain a use-after-free (CWE-416) in the browser's animation timelines component, which CISA describes as allowing code execution in the content process. The flaw is reachable through malicious web content: a crafted page can manipulate animation timelines so that an in-use object is freed, producing exploitable memory corruption. A successful attacker gains code execution in the content process, the sandboxed process that renders web pages, on the machine of the user who loaded the content. All users of Firefox and Firefox ESR are affected by the flaw itself. It is being actively exploited: the vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-10-15 with known ransomware use, and EPSS assigns it a 23.2% probability of exploitation in the next 30 days (98th percentile). Do: Apply Mozilla's patched Firefox/Firefox ESR release immediately and verify the running version via the browser's About Firefox dialog, since many installs only pick up auto-updates after a restart (per CISA's required action: apply mitigations per vendor instructions or discontinue use). Given the known ransomware use, prioritize enterprise ESR rollout and check for managed-update failures, auto-update-disabled installs, or unmanaged Firefox copies on user machines. Note that no public proof-of-concept is known, but KEV listing confirms exploitation, so patching should not wait for PoC availability. | 9.8 | 23% | KEV ransomware |
| masshundreds of millions of users (Firefox's global desktop user base of roughly 150-200M active users, plus enterprise Firefox ESR deployments) |
Full article233 words · extracted from therecord.media · click to collapse
Mozilla has patched a serious security flaw in its Firefox web browser that the company said is being exploited by hackers. In an advisory on Wednesday, Mozilla stated that the bug, tracked as CVE-2024-9680, could allow attackers to execute malicious code within the browser’s content process — an environment where web content is loaded and rendered. The vulnerability was discovered by Damien Schaeffer, a researcher from the cybersecurity firm ESET, in the browser’s animation timelines, which control how animations are presented on web pages. It’s a “use-after-free” flaw that occurs when a program tries to use memory that it has already released or freed. Such memory corruption bugs are typically used to attack and exploit browsers and could potentially give attackers control over the service or further access to the system. Mozilla said it received reports of this vulnerability being exploited in the wild but did not provide further details. The exploit requires no user interaction and can be executed over the network with low complexity. It was given a CVSS score of 9.8 out of 10, signifying a critical vulnerability, according to researchers at Recorded Future. The Record is an editorially independent unit of Recorded Future. To address this vulnerability, Mozilla recommends that users update their Firefox installations to the most current versions available. “Ignoring this update could lead to severe security breaches and data compromise within affected organizations,” researchers warned.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/mozilla-fixes-critical-firefox-bug-exploited-by-hackers