Out-of-bounds Read/Write Vulnerability Affects Firefox

CVE-2024-29943
Currently unrated 🤨

Key Information

Vendor
Mozilla
Status
Firefox
Vendor
CVE Published:
22 March 2024

Badges

👾 Exploit Exists📰 News Worthy

Summary

The vulnerability CVE-2024-29943 affects Firefox, allowing attackers to perform an out-of-bounds read or write on a JavaScript object, enabling remote code execution and sandbox escape. The flaw was exploited during the Pwn2Own Vancouver 2024 hacking competition and affected Firefox versions before 124.0.1. Mozilla has since released security updates to address this vulnerability, but it is imperative for users to promptly update their web browsers to mitigate the risk of potential remote code execution attacks.

Affected Version(s)

Firefox < 124.0.1

News Articles

Timeline

  • 👾

    Exploit exists.

  • First article discovered by Beeping Computers

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database9 News Article(s)

Credit

Manfred Paul via Trend Micro's Zero Day Initiative
.