CVE-2024-9680
About
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.
Rainforest analyst review
A use-after-free in Firefox's Animation timeline code lets a malicious web page cause the browser to reference memory it has already freed and reuse it under attacker control, achieving code execution inside the browser's content process. The user only has to visit a crafted page — the animation objects are freed and then reallocated with attacker-chosen data, redirecting execution. It affects Firefox, Firefox ESR, and the Thunderbird builds that share the engine.
Mozilla confirmed exploitation in the wild, and the bug was reported as part of an attack chain attributed to the RomCom actor that paired this content-process flaw with a sandbox escape to compromise victims who merely opened a booby-trapped site. Content-process RCE by itself is contained by the sandbox, which is precisely why it is chained rather than used alone. Update to Firefox 131.0.2, ESR 128.3.1 or 115.16.1, and the matching Thunderbird releases immediately, since the fix is already outrunning known exploitation.
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1923344
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49039
- https://www.mozilla.org/security/advisories/mfsa2024-51/
- https://www.mozilla.org/security/advisories/mfsa2024-52/
- https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=281992
- https://lists.debian.org/debian-lts-announce/2024/10/msg00005.html
- https://lists.debian.org/debian-lts-announce/2024/10/msg00006.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-9680
Related CVEs
Frequently asked questions
What is CVE-2024-9680?
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.
How severe is CVE-2024-9680?
CVE-2024-9680 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2024-9680 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2024-9680?
Public advisories list the following as affected: debian linux, firefox, thunderbird. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2024-9680?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
