Impact
Memory safety bugs in Mozilla Firefox 133 and Thunderbird 133 can corrupt memory; if exploited, an attacker could achieve arbitrary code execution. The vulnerability is reported as a memory corruption issue that could be used to run code with the privileges of the application. The impact is therefore a critical compromise of confidentiality, integrity, and availability for affected users.
Affected Systems
The affected products are Mozilla Firefox version 133 and Mozilla Thunderbird version 133. Both applications were patched in the subsequent 134 releases, and no other versions are reported to be affected.
Risk and Exploitability
The CVSS score of 9.8 indicates a high severity, and an EPSS score of 9% suggests a lower but non-negligible likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog, but the high CVSS and evidence of memory corruption make it a serious risk. Based on the description, the exact attack vector is not specified; it is inferred that the bug could be triggered by untrusted content, though this inference is not directly supported by the advisory. Existing evidence indicates potential for remote code execution, so users should treat this as a critical threat.
OpenCVE Enrichment
EUVD
Ubuntu USN