publications

publications by categories in reversed chronological order.

2025

  1. CVE-2024-9680: Use-After-Free in Firefox Animation Timelines Leading to Remote Code Execution
    moscovium-mc
    . Analysis and exploit code available here , Nov 2025
    Patched in Firefox 131.0.2, ESR 128.3.1, and 115.16.1. Actively exploited in the wild targeting Tor Browser users.