An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.
The bug consists of improper memory management in the Animation timelines handling module — after an object is freed in memory, it is possible to reference it again (use-after-free), which leads to arbitrary code execution. An attacker can trigger the vulnerability remotely, without authentication and without user interaction, through a crafted website or email message rendered by the vulnerable application. Code execution occurs in the context of the content process.
An attacker can gain full control over the application's content process, which may lead to disclosure of confidential data, data modification, or application destabilization. In combination with other vulnerabilities, further system compromise is possible.
Immediately update Mozilla Firefox to version 131.0.2 or later, Firefox ESR to version 128.3.1 or 115.16.1, Mozilla Thunderbird to version 131.0.1, 128.3.1 or 115.16.0 according to the update channel used in the organization.
Mozilla Firefox in versions below 131.0.2; Mozilla Firefox ESR in versions below 128.3.1 and below 115.16.1; Mozilla Thunderbird in versions below 131.0.1, below 128.3.1 and below 115.16.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDebian
OSDebian11.0Mozilla Firefox
APPMozilla128.1.0 – 128.3.1 (excl.)< 115.16.1< 131.0.2Mozilla Thunderbird
APPMozilla131.0< 115.16.0128.0.1 – 128.3.1 (excl.)
CISA KEV — detailsi
- Vendori
- Mozilla ↗
- Producti
- Firefox
- Added to KEVi
- October 15, 2024
- Remediation deadline (US Federal)i
- November 5, 2024(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.
Related vulnerabilities
GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
RCE przez deserializację PHP w Roundcube Webmail (parametr _from)
Erlang/OTP SSH — nieuwierzytelniony RCE (CVSS 10.0)
Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki