EXECUTIVE SUMMARY:
A critical security vulnerability has been discovered in Firefox, Firefox Extended Support Release (ESR), and tracked as CVE-2024-9680, which has been actively exploited in the wild. This use-after-free bug in the Animation timeline component allows attackers to execute code in the content process, posing a significant risk to users. Exploitation methods may include targeting specific websites or drive-by download campaigns that deceive users into visiting malicious sites. Users are strongly advised to update to the latest versions of Firefox, Firefox ESR to mitigate the risk of active threats. Additionally, the Tor Browser has released an emergency update to address this vulnerability. Prompt action is crucial, as unpatched systems remain vulnerable to potential attacks leveraging this critical flaw.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A critical security vulnerability has been discovered in Firefox, Firefox Extended Support Release (ESR), and tracked as CVE-2024-9680, which has been actively exploited in the wild. This use-after-free bug in the Animation timeline component allows attackers to execute code in the content process, posing a significant risk to users. Exploitation methods may include targeting specific websites or drive-by download campaigns that deceive users into visiting malicious sites. Users are strongly advised to update to the latest versions of Firefox, Firefox ESR to mitigate the risk of active threats. Additionally, the Tor Browser has released an emergency update to address this vulnerability. Prompt action is crucial, as unpatched systems remain vulnerable to potential attacks leveraging this critical flaw.[emaillocker id="1283"]
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/10/mozilla-warns-of-active-exploitation-in.html