CVE-2024-2612: Mozilla Firefox

High severity, CVSS 8.1. EPSS: 1% chance of exploitation in the next 30 days.

If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

Affected products

  • Mozilla Firefox: before 115.9 (fixed in 115.9); before 124.0 (fixed in 124.0)
  • Mozilla Thunderbird: before 115.9 (fixed in 115.9)

Published 2024-03-19. Last modified 2026-06-17.