CVE-2024-9680

Mozilla Firefox: Use-After-Free

As of , CVE-2024-9680 in Mozilla Firefox is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 15 October 2024
US federal deadline
5 November 202421 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
KnownCISA changed it from Unknown to Known on 29 January 2026.
EPSS score
0.23Higher than 97% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.00 on 15 October 2024EPSS on the day CISA listed it.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
Vendor advice: www.mozilla.orgLinks below, from CISA's entry.

What CISA says to do

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA's required action

What the flaw is

Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.

CISA's description

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.

The CVE record's description, from mozilla

CVE published
9 October 2024
Assigned by
mozilla
CVSS
9.8 Critical (CVSS 3.1, from CISA-ADP)
CWE-416
Use After Free
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.
  4. CISA changed its entry. Ransomware use: Unknown to Known.

Firefox: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2015-4495Security Feature BypassMozilla FirefoxPatch this weekMetasploit module; EPSS 0.690.69
CVE-2022-26485Use-After-FreeMozilla FirefoxPatch soon0.14
CVE-2013-1675Information DisclosureMozilla FirefoxPatch soon0.07
CVE-2022-26486Use-After-FreeMozilla FirefoxPatch soon0.02

Read further