Vulnerability record · CVE-2024-9680 · published 9 October 2024
CVE-2024-9680: Mozilla Firefox and Thunderbird use-after-free in Animation timelines
Mozilla · Firefox
A use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports exploitation in the wild, and the affected versions span Firefox before 131.0.2, ESR before 128.3.1 and 115.16.1, and Thunderbird before 131.0.1, 128.3.1 and 115.16.0.
Description
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is a network-reachable, no-interaction use-after-free with confirmed in-the-wild exploitation, CISA KEV listing, ransomware campaign association, and a CVSS score of 9.8.
What it is
A use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports exploitation in the wild, and the affected versions span Firefox before 131.0.2, ESR before 128.3.1 and 115.16.1, and Thunderbird before 131.0.1, 128.3.1 and 115.16.0.
Impact
An attacker gains code execution inside the browser or mail client content process, which can lead to data theft, further compromise of the host, or delivery of additional payloads. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
The vulnerability is network-reachable with no privileges and no user interaction required per the CVSS vector, meaning a crafted page or message can trigger it. It is reached through normal rendering of web content or email in the affected Mozilla products.
Exploitation
CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-15 with a due date of 2024-11-05 and flags known ransomware campaign use, and EPSS gives a 30-day probability of 0.23184 (97.652 percentile). Mozilla states it has reports of exploitation in the wild.
What to do
- Update Firefox to 131.0.2 or later, Firefox ESR to 128.3.1 or 115.16.1 or later, and Thunderbird to 131.0.1, 128.3.1 or 115.16.0 or later.
- Apply the Debian security updates referenced in the Debian LTS announcements for affected packages.
- If immediate patching is not possible, follow CISA KEV guidance to apply vendor mitigations or discontinue use of the affected product.
- Verify update compliance across all endpoints and managed browsers, including ESR channels and mail clients.
Detection
- Monitor for crashes or abnormal terminations in Firefox and Thunderbird content processes that could indicate use-after-free exploitation.
- Hunt for network or email-delivered content that triggers animation timeline behavior in affected versions, correlating with process creation or child process spawning.
- Track endpoint versions against the fixed releases and alert on any host still running Firefox before 131.0.2, ESR before 128.3.1/115.16.1, or Thunderbird before 131.0.1/128.3.1/115.16.0.
- Review logs for post-exploitation activity such as unexpected downloads, script execution, or persistence following browser or mail client use.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-9680 to the Known Exploited Vulnerabilities catalog on 15 October 2024 as "Mozilla Firefox Use-After-Free Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 5 November 2024.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=1923344 | Issue TrackingPermissions Required |
| https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49039 | Not ApplicablePatchVendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2024-51/ | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2024-52/ | Vendor Advisory |
| https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=281992 | Issue Tracking |
| https://lists.debian.org/debian-lts-announce/2024/10/msg00005.html | Mailing List |
| https://lists.debian.org/debian-lts-announce/2024/10/msg00006.html | Mailing List |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-9680 | US Government Resource |
Track CVE-2024-9680 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-9680), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.