← Vulnerability feed

Vulnerability record · CVE-2024-9680 · published 9 October 2024

CVE-2024-9680: Mozilla Firefox and Thunderbird use-after-free in Animation timelines

Mozilla · Firefox

A use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports exploitation in the wild, and the affected versions span Firefox before 131.0.2, ESR before 128.3.1 and 115.16.1, and Thunderbird before 131.0.1, 128.3.1 and 115.16.0.

9.8 CVSS 3.1 Critical CISA KEV since 15 Oct 2024 Known ransomware use EPSS 23% · top 2.3% CWE-416 · Use after free
9.8CVSS 3.1 base score
23%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
8References
4 Aug 2026Last modified by NVD

Description

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is a network-reachable, no-interaction use-after-free with confirmed in-the-wild exploitation, CISA KEV listing, ransomware campaign association, and a CVSS score of 9.8.

What it is

A use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports exploitation in the wild, and the affected versions span Firefox before 131.0.2, ESR before 128.3.1 and 115.16.1, and Thunderbird before 131.0.1, 128.3.1 and 115.16.0.

Impact

An attacker gains code execution inside the browser or mail client content process, which can lead to data theft, further compromise of the host, or delivery of additional payloads. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

The vulnerability is network-reachable with no privileges and no user interaction required per the CVSS vector, meaning a crafted page or message can trigger it. It is reached through normal rendering of web content or email in the affected Mozilla products.

Exploitation

CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-15 with a due date of 2024-11-05 and flags known ransomware campaign use, and EPSS gives a 30-day probability of 0.23184 (97.652 percentile). Mozilla states it has reports of exploitation in the wild.

What to do

  • Update Firefox to 131.0.2 or later, Firefox ESR to 128.3.1 or 115.16.1 or later, and Thunderbird to 131.0.1, 128.3.1 or 115.16.0 or later.
  • Apply the Debian security updates referenced in the Debian LTS announcements for affected packages.
  • If immediate patching is not possible, follow CISA KEV guidance to apply vendor mitigations or discontinue use of the affected product.
  • Verify update compliance across all endpoints and managed browsers, including ESR channels and mail clients.

Detection

  • Monitor for crashes or abnormal terminations in Firefox and Thunderbird content processes that could indicate use-after-free exploitation.
  • Hunt for network or email-delivered content that triggers animation timeline behavior in affected versions, correlating with process creation or child process spawning.
  • Track endpoint versions against the fixed releases and alert on any host still running Firefox before 131.0.2, ESR before 128.3.1/115.16.1, or Thunderbird before 131.0.1/128.3.1/115.16.0.
  • Review logs for post-exploitation activity such as unexpected downloads, script execution, or persistence following browser or mail client use.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-9680 to the Known Exploited Vulnerabilities catalog on 15 October 2024 as "Mozilla Firefox Use-After-Free Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 5 November 2024.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-9680 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed10.0CVE-2019-11708Mozilla Firefox and Thunderbird sandbox escape via Prompt:Open IPC validation flawThe Prompt:Open IPC message between child and parent processes does not sufficiently vet its parameters, letting a compromised child process cause th…KEVEPSS 56%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2023-46604Apache ActiveMQ OpenWire deserialization remote code executionThe Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the br…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2024-9680), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.