CVE-2024-11691

Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. *This bug only affected the application on Apple M series hardware. Other platforms were unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, Thunderbird < 128.5, and Thunderbird < 115.18.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
OR cpe:2.3:h:apple:m1:-:*:*:*:*:*:*:*
cpe:2.3:h:apple:m1_max:-:*:*:*:*:*:*:*
cpe:2.3:h:apple:m1_pro:-:*:*:*:*:*:*:*
cpe:2.3:h:apple:m1_ultra:-:*:*:*:*:*:*:*
cpe:2.3:h:apple:m2:-:*:*:*:*:*:*:*
cpe:2.3:h:apple:m2_max:-:*:*:*:*:*:*:*
cpe:2.3:h:apple:m2_pro:-:*:*:*:*:*:*:*
cpe:2.3:h:apple:m2_ultra:-:*:*:*:*:*:*:*
cpe:2.3:h:apple:m3:-:*:*:*:*:*:*:*
cpe:2.3:h:apple:m3_max:-:*:*:*:*:*:*:*
cpe:2.3:h:apple:m3_pro:-:*:*:*:*:*:*:*
cpe:2.3:h:apple:m3_ultra:-:*:*:*:*:*:*:*
cpe:2.3:h:apple:m4:-:*:*:*:*:*:*:*
cpe:2.3:h:apple:m4_max:-:*:*:*:*:*:*:*
cpe:2.3:h:apple:m4_pro:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-11-26 14:15

Updated : 2025-06-24 16:58


NVD link : CVE-2024-11691

Mitre link : CVE-2024-11691

CVE.ORG link : CVE-2024-11691


JSON object : View

Products Affected

apple

  • m3_max
  • m3_ultra
  • m1_ultra
  • m2_ultra
  • m3
  • m2
  • m4_max
  • m1
  • m2_max
  • m4
  • m3_pro
  • m1_max
  • m4_pro
  • m1_pro
  • m2_pro

mozilla

  • firefox
  • thunderbird
CWE
CWE-787

Out-of-bounds Write