Use-after-free in Mozilla Firefox - CVE-2024-0752
Published: January 23, 2024
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error on macOS if a Firefox update were being applied on a very busy system. A remote attacker can trigger a use-after-free error and execute arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Gentoo Linux
Fedora
www-client/firefox
firefox-flatpak
firefox
How to mitigate CVE-2024-0752
www-client/firefox - update to 104
firefox-flatpak - update to 122.0-1
firefox - addressed in versions 122.0-1.fc38, 122.0-1.fc39