CVE-2024-11691
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
26/11/2024
Last modified:
24/06/2025
Description
Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple&#39;s GPU driver. <br />
*This bug only affected the application on Apple M series hardware. Other platforms were unaffected.* This vulnerability affects Firefox
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | 115.18.0 (excluding) | |
| cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | 116.0 (including) | 128.5.0 (excluding) |
| cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | 129.0 (including) | 133.0 (excluding) |
| cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | 115.18.0 (excluding) | |
| cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | 116.0 (including) | 128.5.0 (excluding) |
| cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | 129.0 (including) | 133.0 (excluding) |
| cpe:2.3:h:apple:m1:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:apple:m1_max:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:apple:m1_pro:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:apple:m1_ultra:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:apple:m2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:apple:m2_max:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:apple:m2_pro:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:apple:m2_ultra:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:apple:m3:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://bugzilla.mozilla.org/show_bug.cgi?id=1914707
- https://bugzilla.mozilla.org/show_bug.cgi?id=1924184
- https://www.mozilla.org/security/advisories/mfsa2024-63/
- https://www.mozilla.org/security/advisories/mfsa2024-64/
- https://www.mozilla.org/security/advisories/mfsa2024-65/
- https://www.mozilla.org/security/advisories/mfsa2024-67/
- https://www.mozilla.org/security/advisories/mfsa2024-68/
- https://www.mozilla.org/security/advisories/mfsa2024-70/



