CVE-2024-11691

HIGH
Published Nov 26, 2024 Modified Jun 24, 2025 CWE-787

Description

Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. *This bug only affected the application on Apple M series hardware. Other platforms were unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, Thunderbird < 128.5, and Thunderbird < 115.18.

Is your site exposed to CVE-2024-11691?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

8.8
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weakness Type (CWE)

CWE-787 Out-of-bounds Write

Affected Products

Vendor Product
mozilla firefox
mozilla firefox
mozilla firefox
mozilla thunderbird
mozilla thunderbird
mozilla thunderbird
apple m1
apple m1_max
apple m1_pro
apple m1_ultra
apple m2
apple m2_max
apple m2_pro
apple m2_ultra
apple m3
apple m3_max
apple m3_pro
apple m3_ultra
apple m4
apple m4_max
apple m4_pro

References

Frequently Asked Questions

What is CVE-2024-11691? +
Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. *This bug only affected the application on Apple M series hardware. Other platforms were unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, Thunderbird < 128.5, and Thunderbird < 115.18. It has a CVSS v3.1 base score of 8.8 (HIGH).
How severe is CVE-2024-11691? +
CVE-2024-11691 has a CVSS v3.1 score of 8.8 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2024-11691? +
CVE-2024-11691 affects products from apple, mozilla, specifically: firefox, m1, m1_max, m1_pro, m1_ultra, m2, m2_max, m2_pro, m2_ultra, m3, m3_max, m3_pro, m3_ultra, m4, m4_max, m4_pro, thunderbird. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-11691? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-11691 — free, no signup required.