CVE-2024-2613: Mozilla Firefox

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulnerability affects Firefox < 124.

Affected products

  • Mozilla Firefox: before 124.0 (fixed in 124.0)

Published 2024-03-19. Last modified 2026-06-17.