Download Firefox

Firefox is no longer supported on Windows 8.1 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox is no longer supported on macOS 10.14 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox Privacy Notice

Mozilla Foundation Security Advisory 2024-15

Security Vulnerabilities fixed in Firefox 124.0.1

Announced
March 22, 2024
Impact
critical
Products
Firefox
Fixed in
  • Firefox 124.0.1

#CVE-2024-29943: Out-of-bounds access via Range Analysis bypass

Reporter
Manfred Paul via Trend Micro's Zero Day Initiative
Impact
critical
Description

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination.

References

#CVE-2024-29944: Privileged JavaScript Execution via Event Handlers

Reporter
Manfred Paul via Trend Micro's Zero Day Initiative
Impact
critical
Description

An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox.

References