CVE-2024-9680: Mozilla Firefox Use-After-Free Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-10-15. EPSS: 23.2% chance of exploitation in the next 30 days.
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.
Affected products
- Debian Debian Linux: version 11.0 only
- Mozilla Firefox: before 115.16.1 (fixed in 115.16.1); before 131.0.2 (fixed in 131.0.2); from 128.1.0, before 128.3.1 (fixed in 128.3.1)
- Mozilla Thunderbird: before 115.16.0 (fixed in 115.16.0); from 128.0.1, before 128.3.1 (fixed in 128.3.1); version 131.0 only
Published 2024-10-09. Last modified 2026-08-04.