CVE-2019-9796: Mozilla Firefox

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single registration is expected. When a registration is later freed with the removal of the animation controller element, the refresh driver incorrectly leaves a dangling pointer to the driver's observer array. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

Affected products

  • Mozilla Firefox: before 60.6.0 (fixed in 60.6.0); before 66.0 (fixed in 66.0)
  • Mozilla Thunderbird: before 60.6.0 (fixed in 60.6.0)

Published 2019-04-26. Last modified 2026-06-17.