logo

Mozilla fixes two Firefox zero-day bugs exploited at Pwn2Own

ID: 40396f5c-a6d3-57ef-a873-b4c7fae8a357

STIX ID: report--40396f5c-a6d3-57ef-a873-b4c7fae8a357

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2024-03-22

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Mozilla released patches for two zero-day Firefox vulnerabilities (an out-of-bounds write CVE-2024-29943 and a privileged JavaScript execution CVE-2024-29944) after they were exploited during the Pwn2Own Vancouver 2024 contest to achieve remote code execution and sandbox escape; fixes were issued in Firefox 124.0.1 and ESR 115.9.1 and no broader in-the-wild exploitation is reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.