ESET reported in November 2024 that the Russia-aligned group tracked as RomCom had chained two zero-day vulnerabilities: CVE-2024-9680, which allowed code execution in the restricted context of Firefox, Thunderbird and the Tor Browser, and CVE-2024-49039 in Windows, which escaped that restriction. Targets were reported in Europe and North America. Mozilla shipped a fix within about 25 hours of the browser flaw being reported on 8 October; Microsoft released its fix on 12 November.
Zero-Click Is The Property That Matters
Chained together the two flaws required no user interaction. Visiting a page was sufficient — no attachment, no macro, no decision by the person at the keyboard.
Almost every intrusion in this database begins with somebody doing something reasonable: opening a document, answering a call, considering a job. This one removes even that, which also removes every control that depends on user judgement.
A Sandbox Is One Half Of A Pair
The browser flaw only ran code inside the sandbox. On its own it was contained, and the Windows flaw is what made it matter.
Severity scored per vulnerability misses this. Two flaws individually rated as manageable combine into remote compromise with no interaction, and no scoring scheme in common use represents the pair.
Twenty-Five Hours
Mozilla’s turnaround on the browser flaw is the fastest vendor response recorded in this file set.
It is worth naming against the Unisoc case in 2026, where researchers could not get the vendor to reply at all. The range between those two is the whole of what coordinated disclosure delivers in practice.
Compiled from ESET’s published research and public reporting, listed below. Attribution to a Russia-aligned group is the researchers’ assessment; we attribute nothing to any state. No victim count has been published. Corrections: corrections@forensicpost.com.