2024 · Browser Security
RomCom APT: Full Chain Analysis of CVE-2024-9680
Complete technical dissection of the Firefox zero-day exploited in the wild by RomCom APT — WASM type
confusion triggering JIT compiler hijacking, chained with Win32k.sys UAF for SYSTEM-level RCE. Includes
decoded JavaScript, disassembled WebAssembly, reconstructed shellcode sequences, and full MITRE ATT&CK TTP
mapping.
exploit
browser
CVE-2024-9680
APT