Netskope Threat Labs

BROWSER-FIREFOX Mozilla Firefox ESR NotifyTimeChange use after free attempt

IPS-SWG

1 SID: 40888

First seen
February 2022
Last seen
October 2026

Detects web content that exploits CVE-2016-9079, a use-after-free in Firefox's SVG animation timing that can allow code execution. The rule matches SVG animation control calls, such as pauseAnimations and begin, that public exploits use to free the animation timeline while it remains in use, and Firefox ESR 45.5.1 fixed the flaw after it reached targets through malvertising.