CVE-2024-11691
Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. *This bug only affected the application on Apple M series hardware. Other platforms were unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, Thunderbird < 128.5, and Thunderbird < 115.18.
Published:Nov 26, 2024
Last Modified:Jun 24, 2025
EPS:Nov 26, 2024
EPSS Score:0.00428
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Apple
Product
M1
Apple
M1
Vendor
Apple
Product
M1 Max
Apple
M1 Max
Vendor
Apple
Product
M1 Pro
Apple
M1 Pro
Vendor
Apple
Product
M1 Ultra
Apple
M1 Ultra
Vendor
Apple
Product
M2
Apple
M2
Vendor
Apple
Product
M2 Max
Apple
M2 Max
Vendor
Apple
Product
M2 Pro
Apple
M2 Pro
Vendor
Apple
Product
M2 Ultra
Apple
M2 Ultra
Vendor
Apple
Product
M3
Apple
M3
Vendor
Apple
Product
M3 Max
Apple
M3 Max
Vendor
Apple
Product
M3 Pro
Apple
M3 Pro
Vendor
Apple
Product
M3 Ultra
Apple
M3 Ultra
Vendor
Apple
Product
M4
Apple
M4
Vendor
Apple
Product
M4 Max
Apple
M4 Max
Vendor
Apple
Product
M4 Pro
Apple
M4 Pro
Vendor
Mozilla
Product
Firefox
Mozilla
Firefox
Vendor
Mozilla
Product
Firefox Esr
Mozilla
Firefox Esr
Vendor
Mozilla
Product
Thunderbird
Mozilla
Thunderbird
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
