#VU100964 Double free in Firefox for Android and Mozilla Firefox - CVE-2024-11704
Published: November 26, 2024 / Updated: February 4, 2025
Firefox for Android
Mozilla Firefox
Mozilla
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the sec_pkcs7_decoder_start_decrypt() function. A remote attacker can trick the victim into connecting to a specially crafted website, trigger a double free error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.