Impact
This vulnerability is a use‑after‑free flaw (CWE‑416) in Firefox’s Disability Access APIs. The bug permits an attacker to access memory that has already been freed, which can lead to arbitrary code execution or a targeted crash. The flaw has a high severity with a CVSS score of 9.8 and is identified as a serious risk for any affected versions.
Affected Systems
Mozilla Firefox versions earlier than 146.0.1 are affected. The problem originates in the Disability Access APIs component that provides accessibility features for users with disabilities.
Risk and Exploitability
The CVSS score of 9.8 indicates high risk; however, the EPSS score of less than 1% signals that the likelihood of exploitation is currently low. The flaw is not listed in the CISA KEV catalog, so no active exploitation has been reported. Attackers would need to lure a user to a page that exercises the vulnerable accessibility APIs, which likely requires malicious JavaScript or a crafted web page.
OpenCVE Enrichment