CVE-2024-7524: Mozilla Firefox

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" mode, an attacker able to inject an HTML element could have used a DOM Clobbering attack on some of the shims and achieved XSS, bypassing the CSP strict-dynamic protection. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.

Affected products

  • Mozilla Firefox: before 129.0 (fixed in 129.0)
  • Mozilla Firefox ESR: before 115.14 (fixed in 115.14); from 116.0, before 128.1 (fixed in 128.1)

Published 2024-08-06. Last modified 2026-06-17.