Download Firefox

Firefox is no longer supported on Windows 8.1 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox is no longer supported on macOS 10.14 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox Privacy Notice

Mozilla Foundation Security Advisory 2024-16

Security Vulnerabilities fixed in Firefox ESR 115.9.1

Announced
March 22, 2024
Impact
critical
Products
Firefox ESR
Fixed in
  • Firefox ESR 115.9.1

#CVE-2024-29944: Privileged JavaScript Execution via Event Handlers

Reporter
Manfred Paul via Trend Micro's Zero Day Initiative
Impact
critical
Description

An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox.

References