Firefox Vulnerability Affects Users of < 130 and Firefox ESR < 128.2
CVE-2024-8385
9.8CRITICAL
Key Information:
- Vendor
- Mozilla
- Vendor
- CVE Published:
- 3 September 2024
Summary
The reported vulnerability arises from inconsistencies in the management of StructFields and ArrayTypes within WebAssembly (WASM), leading to a type confusion scenario. This flaw may allow an attacker to execute arbitrary code or manipulate data structures, potentially compromising user data integrity and security. The affected versions of Firefox and Thunderbird are particularly vulnerable due to the inadequacies in the WASM handling process, necessitating prompt updates to mitigate risks associated with this issue.
Affected Version(s)
Firefox < 130
Firefox ESR < 128.2
Thunderbird < 128.2
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Seunghyun Lee