CVE-2024-3856: Mozilla Firefox

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects Firefox < 125.

Affected products

  • Mozilla Firefox: before 125.0 (fixed in 125.0)

Published 2024-04-16. Last modified 2026-06-17.