{"id":"CVE-2024-9680","title":"An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines","summary":"An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-416","CWE-416"],"vendor":"mozilla","product":"firefox","affected":["firefox < 115.16.1","firefox < 131.0.2","firefox >= 128.1.0, < 128.3.1","thunderbird < 115.16.0","thunderbird >= 128.0.1, < 128.3.1","thunderbird = 131.0","debian_linux = 11.0"],"patched":["firefox 128.3.1","thunderbird 128.3.1"],"published":"2024-10-09","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-9680","references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1923344","label":"security@mozilla.org"},{"url":"https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49039","label":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2024-51/","label":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2024-52/","label":"security@mozilla.org"},{"url":"https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=281992","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2024/10/msg00005.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2024/10/msg00006.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-9680","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.23184,"epssPercentile":0.97709,"kev":true,"kevDateAdded":"2024-10-15","kevDueDate":"2024-11-05","kevRansomware":true,"exploited":true,"zeroDay":true,"ingestedAt":"2026-08-04T05:36:12.514Z","exploits":{"github":3,"githubRepos":["https://github.com/tdonaworth/Firefox-CVE-2024-9680","https://github.com/PraiseImafidon/Version_Vulnerability_Scanner","https://github.com/moscovium-mc/Tor-0day-JavaScript-Exploit"],"checkedAt":"2026-09-21T15:26:53.075Z"},"exploitAvailable":true,"slug":"CVE-2024-9680","body":"## Overview\n\nAn attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.\n\n## Affected\n\n- `firefox < 115.16.1`\n- `firefox < 131.0.2`\n- `firefox >= 128.1.0, < 128.3.1`\n- `thunderbird < 115.16.0`\n- `thunderbird >= 128.0.1, < 128.3.1`\n- `thunderbird = 131.0`\n- `debian_linux = 11.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `firefox 128.3.1`\n- `thunderbird 128.3.1`","depth":"hadal","depthScore":89,"depthScoreParts":{"impact":53.9,"likelihood":4.6,"exploitation":25,"ransomware":5},"changes":[{"seq":4756,"id":"CVE-2024-9680","ts":1788887203725,"field":"exploit_available","old":"false","new":"true"},{"seq":3639,"id":"CVE-2024-9680","ts":1788886319909,"field":"exploit_available","old":"true","new":"false"},{"seq":2490,"id":"CVE-2024-9680","ts":1788882988415,"field":"exploit_available","old":"false","new":"true"},{"seq":1519,"id":"CVE-2024-9680","ts":1788882402017,"field":"exploit_available","old":"true","new":"false"},{"seq":633,"id":"CVE-2024-9680","ts":1788881839756,"field":"exploit_available","old":"false","new":"true"}]}