Impact
The vulnerability is a use‑after‑free occurring in the MediaTrackGraphImpl::GetInstance() actor of Mozilla’s media handling stack. Premature deallocation followed by subsequent access can corrupt memory, which for a process with sufficient privileges could permit an attacker to execute arbitrary code or crash the application. The CVSS score of 9.8 reflects the severe potential impact, although the advisory itself does not detail a confirmed execution path.
Affected Systems
All releases of Mozilla Firefox and Firefox ESR before version 144 and 140.4 respectively, and all releases of Mozilla Thunderbird and Thunderbird ESR before version 144 and 140.4 respectively, are affected. The fix is incorporated in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird ESR 140.4.
Risk and Exploitability
The high CVSS score indicates a serious outcome if the flaw is exploited, while the EPSS score of < 1% suggests that exploit attempts are currently rare. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, but the combination of severity and low exploitation probability still warrants focused remediation to prevent future attacks that could leverage similar exploitation techniques.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN