CVE-2024-9393
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-9393 is a newly disclosed vulnerability that enables an attacker to execute arbitrary JavaScript code under the `resource://pdf.js` origin in Firefox and Thunderbird browsers. Exploiting this weakness, an adversary can potentially access cross-origin PDF content, bypassing the Site Isolation feature's restrictions on desktop clients. Notably, full cross-origin access is achievable on Android versions of these applications. This vulnerability affects various outdated versions of Firefox (< 131), Firefox ESR (< 128.3 and < 115.16), Thunderbird (< 128.3), and Thunderbird (< 131).
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.