CVE-2024-9680

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 6 articles

EPSS Score

Source: FIRST.org · 2026-05-24
30.81%
probability
This CVE has a 30.81% probability of being exploited in the next 30 days.
0% Top 96.8th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Use-after-free in Animation timeline

Attack Intelligence

Google Project Zero

Patched
Oct. 9, 2024
Reported by
Damien Schaeffer from ESET
Root Cause Analysis
???

Exploits & PoC

tdonaworth/Firefox-CVE-2024-9680

PoC CVE-2024-9680 — tdonaworth/Firefox-CVE-2024-9680

11
PraiseImafidon/Version_Vulnerability_Scanner

A vulnerability scanner for Firefox and Thunderbird that checks if your versions are out of date and susceptible to CVE-2024-9680.

1
2 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
95%
EPSS 30.81%
Mentions 6
Last Seen Nov 26, 2024

CNA Information

Analyst Note

CVE-2024-9680 is a critical use-after-free vulnerability in Firefox with a CVSS score of 9.8, confirmed active exploitation in the wild by threat actors including Russian RomCom hackers, and documented by reputable sources including BleepingComputer and CERT-EU. Mozilla has issued patches across multiple affected versions (Firefox, Firefox ESR, and Thunderbird), validating the vulnerability's authenticity and severity.

Threat Actors 14

Turla Group
apt_group Information theft and espionage Russian Federation
Cobalt
apt_group Financial crime 🇷🇺 RU
APT 28
apt_group Information theft and espionage 🇷🇺 RU
Kimsuky
apt_group Information theft and espionage 🇰🇷 KR
Hacking Team
apt_group 🇮🇹 IT
Gamaredon Group
apt_group Information theft and espionage 🇷🇺 RU
ELECTRUM
apt_group Information theft and espionage 🇷🇺 RU
Group 27
apt_group Information theft and espionage 🇨🇳 CN
RomCom
apt_group Financial gain 🇷🇺 RU
Rocke
apt_group 🇨🇳 CN
Void Rabisu
apt_group Financial gain 🇷🇺 RU
Red Dev 17
apt_group 🇨🇳 CN
Red October
apt_group 🇷🇺 RU
Mana Team
apt_group 🇨🇳 CN

Triage Info

Decided atMar 03, 2026