Mozilla fixes Firefox zero-day actively exploited in attacks

Share:

Mozilla has issued an emergency security update for the Firefox browser to address a critical use-after-free vulnerability that is currently exploited in attacks.

The vulnerability, tracked as CVE-2024-9680, and discovered by ESET researcher Damien Schaeffer, is a use-after-free in Animation timelines.

This type of flaw occurs when memory that has been freed is still used by the program, allowing malicious actors to add their own malicious data to the memory region to perform code execution.

Animation timelines, part of Firefox’s Web Animations API, are a mechanism that controls and synchronizes animations on web pages.

“An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines,” reads the security bulletin.

“We have had reports of this vulnerability being exploited in the wild.”

The vulnerability impacts the latest Firefox (standard release) and the extended support releases (ESR).

Fixes have been made available in the below versions, which users are recommended to upgrade to immediately:

  • Firefox 131.0.2
  • Firefox ESR 115.16.1
  • Firefox ESR 128.3.1

Given the active exploitation status for CVE-2024-9680 and the lack of any information on how people are targeted, upgrading to the latest versions is essential.

To upgrade to the latest version, launch Firefox and go to Settings -> Help -> About Firefox, and the update should start automatically. A restart of the program will be required for the changes to apply.

BleepingComputer has contacted both Mozilla and ESET to learn more about the vulnerability, how it’s being exploited, and against whom, and we will update this post when we receive more information.

Throughout 2024, so far, Mozilla had to fix zero-day vulnerabilities on Firefox only once.

On March 22, the internet company released security updates to address CVE-2024-29943 and CVE-2024-29944, both critical-severity issues discovered and demonstrated by Manfred Paul during the Pwn2Own Vancouver 2024 hacking competition.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
4:23 pm, Jun 12, 2025
weather icon 24°C
L: 23° | H: 26°
broken clouds
Humidity: 63 %
Pressure: 1011 mb
Wind: 11 mph S
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:17 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
23° | 26°°C 0 mm 0% 9 mph 71 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
16° | 27°°C 1 mm 100% 7 mph 94 % 1019 mb 0 mm/h
Sat Jun 14 10:00 pm
weather icon
17° | 23°°C 1 mm 100% 13 mph 96 % 1019 mb 0 mm/h
Sun Jun 15 10:00 pm
weather icon
13° | 22°°C 0.46 mm 46% 10 mph 84 % 1025 mb 0 mm/h
Mon Jun 16 10:00 pm
weather icon
14° | 25°°C 0 mm 0% 7 mph 86 % 1027 mb 0 mm/h
Today 7:00 pm
weather icon
24° | 24°°C 0 mm 0% 9 mph 62 % 1011 mb 0 mm/h
Today 10:00 pm
weather icon
19° | 21°°C 0 mm 0% 4 mph 71 % 1014 mb 0 mm/h
Tomorrow 1:00 am
weather icon
17° | 17°°C 0 mm 0% 3 mph 80 % 1016 mb 0 mm/h
Tomorrow 4:00 am
weather icon
16° | 16°°C 0 mm 0% 3 mph 84 % 1017 mb 0 mm/h
Tomorrow 7:00 am
weather icon
18° | 18°°C 0 mm 0% 7 mph 79 % 1018 mb 0 mm/h
Tomorrow 10:00 am
weather icon
22° | 22°°C 0 mm 0% 7 mph 60 % 1019 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
26° | 26°°C 0 mm 0% 6 mph 41 % 1019 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
27° | 27°°C 0 mm 0% 7 mph 40 % 1019 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,843.15
-1.94%
Ethereum(ETH)
€2,385.76
-2.48%
Tether(USDT)
€0.86
0.00%
XRP(XRP)
€1.94
-3.26%
Solana(SOL)
€137.78
-3.91%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.163467
-6.01%
Shiba Inu(SHIB)
€0.000011
-5.69%
Pepe(PEPE)
€0.000010
-5.84%
Peanut the Squirrel(PNUT)
€0.236997
-5.02%
Scroll to Top