Skip to Main Content

You Need to Update Firefox ASAP

A new zero-day security flaw has an active exploit.
A screenshot of the Firefox browser on an orange background
Credit: evergrin / Shutterstock.com

Security vulnerabilities are unfortunately inevitable, whatever program you're using. Software is never perfect, and there will always be an unforeseen flaw that might allow a bad actors to exploit an application and its users. The key is to find those flaws before the bad actors do, and patch them before anyone has the chance to discover how to exploit them.

Unfortunately, it's too late for that when it comes to Firefox's latest security vulnerability. Mozilla, Firefox's developer, announced in a security advisory on Wednesday that it had patched a "critical" flaw with the browser. The company says the issue, CVE-2024-9680, is a "use-after-free" flaw affecting Animation timelines. Use-after-free flaws occur when a system frees up memory, but a program continues to access it anyway. While this can result in general software issues, it also opens the door for bad actors to jump in. In this case, Mozilla confirms the flaw allows an attacker to "achieve code execution," or run their own malicious code, through the exploit.

What makes this particular flaw a critical issue is that it is a zero-day with an active exploit. A zero-day is a flaw discovered before the developer (Mozilla) has a chance to patch it. While not all zero-days are actively exploited, this one has been: Mozilla says they have reports of active exploitation in the wild, although it's not clear by whom or to what degree.

No matter the case, all Firefox users should update their browsers as soon as possible to this latest version, 131.0.2, if they haven't done so already.

How to update Firefox and patch this security vulnerability

To update your Firefox browser, open the app on your computer, then head to Settings. Under General, scroll down to Firefox Updates (or search "Firefox Updates" at the top of the page), then click Check for updates. If one is available, follow the on-screen instructions to install the patch.

artist rendition of Jake Peterson
Jake Peterson
Senior Technology Editor

Jake Peterson is Lifehacker’s Senior Technology Editor. He has a BFA in Film & TV from NYU, where he specialized in writing. Jake has been helping people with their technology professionally since 2016, beginning as technical specialist at New York’s 5th Avenue Apple Store, then as a writer for the website Gadget Hacks. In that time, he wrote and edited thousands of news and how-to articles about iPhones and Androids, including reporting on live demos from product launches from Samsung and Google. In 2021, he moved to Lifehacker and covers everything from the best uses of AI in your daily life to which MacBook to buy. His team covers all things tech, including smartphones, computers, game consoles, and subscriptions. He lives in Connecticut.

Read Jake's full bio