CVE-2024-8381: Mozilla Firefox

Critical severity, CVSS 9.8. EPSS: 4.4% chance of exploitation in the next 30 days.

A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.

Affected products

  • Mozilla Firefox: before 130.0 (fixed in 130.0)
  • Mozilla Firefox ESR: before 115.15 (fixed in 115.15); from 128.0, before 128.2 (fixed in 128.2)

Published 2024-09-03. Last modified 2026-06-17.