Mozilla Firefox Security Update – 10 October 2024

Mozilla has released an updated Firefox version 131.0.2, Firefox ESR versions 128.3.1, and 115.16.1 to fix a zero-day vulnerability.

The addressed vulnerability could allow the remote attacker to execute arbitrary code in the content process, and gain access to the affected products by exploiting a use-after-free in Animation timelines.

Mozilla Firefox Code Execution Vulnerability (CVE-2024-9680):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

It should be highlighted that Mozilla is aware that vulnerability “CVE-2024-9680” is being exploited in the wild.

Vulnerabilities

CVE-2024-9680

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Mozilla Firefox Security Advisory

References