Impact
Incorrect boundary checks in the JavaScript: WebAssembly component can lead to out‑of‑bounds memory accesses, possibly corrupting memory when malicious content is processed. The flaw aligns with buffer overrun issues and improper error handling.
Affected Systems
Mozilla Firefox and Thunderbird, including ESR versions, are affected in releases older than Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
Risk and Exploitability
The CVSS score of 7.5 indicates moderate to high risk, while the EPSS score of less than 1% suggests a low exploitation probability and the vulnerability is not listed in CISA KEV. An attacker might cause memory corruption by delivering a WebAssembly module that violates boundaries, thereby affecting the process that loads the module and potentially compromising user data.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN