Firefox Vulnerability Affects Users of < 130 and Firefox ESR < 128.2
CVE-2024-8385

9.8CRITICAL

Key Information:

Vendor
Mozilla
Vendor
CVE Published:
3 September 2024

Summary

The reported vulnerability arises from inconsistencies in the management of StructFields and ArrayTypes within WebAssembly (WASM), leading to a type confusion scenario. This flaw may allow an attacker to execute arbitrary code or manipulate data structures, potentially compromising user data integrity and security. The affected versions of Firefox and Thunderbird are particularly vulnerable due to the inadequacies in the WASM handling process, necessitating prompt updates to mitigate risks associated with this issue.

Affected Version(s)

Firefox < 130

Firefox ESR < 128.2

Thunderbird < 128.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Seunghyun Lee
.