Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver.
*This bug only affected the application on Apple M series hardware. Other platforms were unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, Thunderbird < 128.5, and Thunderbird < 115.18.
References
| Link | Resource |
|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=1914707 | Issue Tracking |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1924184 | Issue Tracking |
| https://www.mozilla.org/security/advisories/mfsa2024-63/ | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2024-64/ | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2024-65/ | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2024-67/ | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2024-68/ | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2024-70/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2024-11-26 14:15
Updated : 2025-06-24 16:58
NVD link : CVE-2024-11691
Mitre link : CVE-2024-11691
CVE.ORG link : CVE-2024-11691
JSON object : View
Products Affected
apple
- m3_max
- m3_ultra
- m1_ultra
- m2_ultra
- m3
- m2
- m4_max
- m1
- m2_max
- m4
- m3_pro
- m1_max
- m4_pro
- m1_pro
- m2_pro
mozilla
- firefox
- thunderbird
CWE
CWE-787
Out-of-bounds Write
