CVE-2024-8384: Mozilla Firefox

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory corruption. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.

Affected products

  • Mozilla Firefox: before 130.0 (fixed in 130.0)
  • Mozilla Firefox ESR: before 115.15 (fixed in 115.15); from 128.0, before 128.2 (fixed in 128.2)

Published 2024-09-03. Last modified 2026-06-17.