CVE-2024-29943 is a memory-safety vulnerability in Firefox versions earlier than 124.0.1. An attacker can fool range-based bounds-check elimination for a JavaScript object, causing an out-of-bounds read or write. Successful exploitation can result in arbitrary code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a real end-to-end exploit for CVE-2024-29943 against vulnerable Mozilla SpiderMonkey/Firefox builds, not just a trigger or detector. It contains 5 files total: README.md for documentation, exploit.js as the main exploit, poc.js as a minimal bug trigger, gen_wasm.py to generate a custom WebAssembly module carrying shellcode, and test.gdb to help derive build-specific internal offsets. The exploit structure is clearly staged. First, exploit.js abuses the IonMonkey range-analysis bug in Object.keys(x).length to obtain out-of-bounds access on a Uint8Array. From that memory corruption primitive, it corrupts adjacent ArrayBuffer state to build addrof/fakeobj/arbitrary read-write capabilities. Next, it instantiates a handcrafted WebAssembly module whose f64.const immediates contain attacker-controlled shellcode bytes. The exploit then walks SpiderMonkey internal wasm structures (WasmInstanceObject -> wasm::Instance -> wasm::Code -> CodeTier -> ModuleSegment) to locate the RWX JIT code page, scans for a marker constant, identifies the shellcode location, and patches the wasm export interpreter-entry stub so a call to instance.exports.add() jumps directly to the shellcode. The repository is operational rather than a bare PoC because it includes a working payload path and a default native shellcode payload. The default shellcode is Linux x86-64 machine code that resolves system() using libxul/GOT-relative offsets and executes gnome-calculator. gen_wasm.py can also embed a user-supplied shellcode binary, making the payload somewhat customizable, though the exploit still relies on hardcoded SpiderMonkey object offsets and build assumptions. There are no external network callbacks or C2 endpoints in the code. The notable fingerprintable artifacts are local/runtime targets and references: the vulnerable JS shell binary ./js, the vulnerable gecko-dev commit afbdf6822c9e9f9b6d44b9ea6904cb10878126b1, internal SpiderMonkey header paths used to derive offsets, the shellcode marker constant 0x666e616d37130542, and the default command string gnome-calculator. The attack vector is primarily browser/web engine exploitation, though the provided reproduction path is local execution against the SpiderMonkey JS shell on Linux x86-64.
This repository contains a working exploit for CVE-2024-29943, a SpiderMonkey JIT (Just-In-Time) bug in Mozilla Firefox 124.0 that allows for remote code execution (RCE) on Windows 11. The exploit leverages integer range inconsistencies and bound check elimination in the JIT compiler to achieve out-of-bounds (OOB) read/write primitives. Two main exploit scripts are provided: - Exploit_64.js: Uses BigUint64Array for OOB memory manipulation, requiring significant RAM (~20GB). - Exploit_8.js: Uses Uint8Array for OOB writes, reducing RAM requirements (~10GB). Both scripts perform heap spraying and manipulate JavaScript arrays to corrupt memory, ultimately hijacking the JIT-compiled code to execute attacker-controlled shellcode. The shellcode is encoded as floating-point numbers and, when triggered, launches calc.exe as a demonstration of code execution. The exploit is tailored for Windows and requires the target to run the vulnerable Firefox version with specific mitigations disabled. No network or external endpoints are referenced; the attack is fully browser-based and local to the JavaScript engine. The README provides context, usage instructions, and credits to the original researcher.
This repository contains a working exploit for CVE-2024-29943, a SpiderMonkey JIT bug that can be leveraged for remote code execution. The main exploit logic is in 'Exploit.js', which demonstrates a full exploit chain: it manipulates JavaScript array bounds and JIT optimizations to achieve arbitrary memory read/write, then hijacks a JIT-compiled function pointer to execute attacker-controlled shellcode. The exploit is highly technical and operational, requiring a vulnerable build of SpiderMonkey (as referenced by a specific commit) and specific runtime flags to disable mitigations. 'PoC.js' and 'Inconsistency.js' provide proof-of-concept and minimal triggers for the underlying bug, while 'JitSpew.patch' is a debugging patch for SpiderMonkey's JIT internals. The README documents the vulnerability, reproduction steps, and references. No network or external endpoints are present; the exploit is local and targets the JavaScript engine directly. The exploit demonstrates advanced exploitation techniques, including heap spraying, type confusion, and JIT function pointer manipulation, culminating in arbitrary code execution.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Firefox zero-day vulnerability identified and exploited during Pwn2Own Vancouver 2024.
A critical Firefox vulnerability involving bypass of JavaScript object memory bounds checks, enabling out-of-bounds read/write and arbitrary code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.