CVE-2024-9680
A flaw in how animation timelines are handled allows attackers to execute malicious code within the content process of the browser or email client. This vulnerability has been observed being exploited in the wild.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of Mozilla Firefox (versions prior to 131.0.2, 128.3.1, and 115.16.1) and Mozilla Thunderbird (versions prior to 131.0.1, 128.3.1, and 115.16.0).
Real-world impact
An attacker could remotely run unauthorized code on your computer, potentially taking control of the application's processes.
Why this severity
This is a critical vulnerability because it can be exploited remotely over the network without any user interaction or special privileges, allowing for full control over the application's content process.
What to do about it
- 01Upgrade Firefox to version 131.0.2 or later.
- 02Upgrade Firefox ESR to version 128.3.1 or later.
- 03Upgrade Firefox ESR to version 115.16.1 or later.
- 04Upgrade Thunderbird to version 131.0.1 or later.
- 05Upgrade Thunderbird to version 128.3.1 or later.
- 06Upgrade Thunderbird to version 115.16.0 or later.
- ›Apply mitigations per vendor instructions
- ›Discontinue use of the product if mitigations are unavailable
CISA KEV required action
Timeline
- Oct 9, 2024 · Oct 9, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Oct 15, 2024 · Oct 15, 2024Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Nov 5, 2024 · Nov 5, 2024CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 2d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- bugzilla.mozilla.org/show_bug.cgiissue trackingpermissions required
- msrc.microsoft.com/update-guide/en-US/vulnerab…not applicablepatchvendor advisory
- mozilla.org/security/advisories/mfsa202…vendor advisory
- mozilla.org/security/advisories/mfsa202…vendor advisory
- bugs.freebsd.org/bugzilla/show_bug.cgiissue tracking
- lists.debian.org/debian-lts-announce/2024/10…mailing list
- lists.debian.org/debian-lts-announce/2024/10…mailing list
- cisa.gov/known-exploited-vulnerabili…us government resource