The corrective releases of Firefox 131.0.2, Firefox ESR 115.16.1, Firefox ESR 128.3.1, and Tor Browser 13.5.7 have been published, addressing a critical vulnerability (CVE-2024-9680) that could lead to code execution at the process level when opening specially crafted pages. The vulnerability is caused by a use-after-free issue in the implementation of the AnimationTimeline API, which is used for synchronization and precise control of animated effects on web pages. The danger of the vulnerability is exacerbated by the fact that ESET has identified instances of its exploitation in attacks (0-day) prior to the release of the fix. Detailed information about the nature of the vulnerability has not yet been disclosed.
Additionally, it is noteworthy to mention the discovery of issues in the Firefox 131 release (1, 2, 3) that lead to interface element display problems when launching the browser in X11/Xorg environments without a compositing manager. These issues manifest in Xfce with compositing mode turned off in the settings and in simple window managers. For example, shadows and rounded corners of pop-up menus disappear, and a black background appears instead of transparency on the scroll indicator.
Source: opennet.ru
