CVE-2024-9680 — An attacker was able to achieve code execution in the content process by exploit
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox E
Published
2024-10-09T13:15:12.090
Last modified
2026-08-04T05:16:32.530
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV — Actively Exploited
01What is this vulnerability?
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.
02Affected products
No structured affected-product list available — see references below for vendor advisories.
03Active exploitation status
Yes — actively exploited. Added to the CISA KEV catalog on 2024-10-15. Ransomware use: Known.
04Recommended remediation
- Patch to a fixed version listed in the vendor advisory (see references below).
- Mitigate with WAF rules, network egress filters, or feature flags where the patch is not yet available.
- Hunt historical logs for exploitation indicators — see Detection signatures below.
05Technical details
For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.
06Detection signatures
Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice:
Open in Sigma generator →
07Related CVEs
08Timeline
- Published: 2024-10-09T13:15:12.090
- Last modified: 2026-08-04T05:16:32.530
- Added to CISA KEV: 2024-10-15
09References
- bugzilla.mozilla.org — https://bugzilla.mozilla.org/show_bug.cgi?id=1923344
- msrc.microsoft.com — https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49039
- www.mozilla.org — https://www.mozilla.org/security/advisories/mfsa2024-51/
- www.mozilla.org — https://www.mozilla.org/security/advisories/mfsa2024-52/
- bugs.freebsd.org — https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=281992
- lists.debian.org — https://lists.debian.org/debian-lts-announce/2024/10/msg00005.html
- lists.debian.org — https://lists.debian.org/debian-lts-announce/2024/10/msg00006.html
- www.cisa.gov — https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-…
Want this in your SOAR or SIEM?
SARA's API returns EPSS, CVSS, KEV, and an analyst-grade summary in one call.
Read the API reference →