Vulnerability record · CVE-2016-9079 · published 11 June 2018
CVE-2016-9079: Firefox and Tor Browser SVG Animation use-after-free
Debian · Debian Linux
A use-after-free flaw in SVG Animation affects Firefox before 50.0.2, Firefox ESR before 45.5.1, and Thunderbird before 45.5.1. Mozilla reports an exploit built on this vulnerability was found in the wild targeting Firefox and Tor Browser users on Windows, making it a confirmed real-world attack rather than a theoretical bug.
Description
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityConfirmed in-the-wild exploitation, CISA KEV listing, and a 99.7th percentile EPSS score make this an urgent patch target despite the moderate CVSS base score of 7.5.
What it is
A use-after-free flaw in SVG Animation affects Firefox before 50.0.2, Firefox ESR before 45.5.1, and Thunderbird before 45.5.1. Mozilla reports an exploit built on this vulnerability was found in the wild targeting Firefox and Tor Browser users on Windows, making it a confirmed real-world attack rather than a theoretical bug.
Impact
The CVSS vector rates only confidentiality impact (C:H) with no integrity or availability effect, so the recorded scoring describes information disclosure. However, a use-after-free in a browser rendering path is typically a memory-corruption primitive, and the in-the-wild exploit reports indicate the practical impact can exceed the scored vector.
Attack surface
Reached over the network with no privileges and no user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N), meaning a crafted SVG animation delivered to the browser can trigger the flaw. The description confirms the exploit targeted Firefox and Tor Browser users on Windows.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2023-06-22 with a 2023-07-13 remediation due date, and references carry Exploit tags including Exploit-DB entries 41151 and 42327; EPSS is 0.87423 (99.7th percentile). Exploitation is confirmed in the wild.
What to do
- Update Firefox to 50.0.2 or later, Firefox ESR to 45.5.1 or later, and Thunderbird to 45.5.1 or later per Mozilla advisory mfsa2016-92.
- Apply the vendor errata for Linux distributions carrying these packages (Red Hat RHSA-2016-2843 and RHSA-2016-2850, Debian DSA-3730, Gentoo GLSA 201701-15 and 201701-35).
- Update Tor Browser to a build based on a fixed Firefox ESR, since Tor Browser users were a named target of the in-the-wild exploit.
- If immediate patching is not possible, restrict browsing to trusted sites and treat unsolicited SVG content as hostile, but note this is a stopgap and not a substitute for the update.
Detection
- Hunt for Firefox, Firefox ESR, Thunderbird, or Tor Browser versions below the fixed releases (50.0.2, 45.5.1, 45.5.1) across endpoints and report any that remain.
- Review proxy, IDS, and browser telemetry for SVG or animation content delivered from unusual or low-reputation hosts to Firefox or Tor Browser clients.
- Look for browser process crashes followed by unexpected child processes or outbound connections, which can indicate a use-after-free exploit chain.
- Check whether the CISA KEV due date of 2023-07-13 was met in your environment and flag any assets still unpatched past it.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-9079 to the Known Exploited Vulnerabilities catalog on 22 June 2023 as "Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 July 2023.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-9079 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-9079), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.