Impact
Sandbox escape in the Messaging System component of Mozilla products. This vulnerability allows code to escape the application sandbox, potentially permitting execution outside the protected environment. It was resolved in Firefox 147 and Thunderbird 147.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. Versions of both products released before 147 contain the flaw. Users running earlier releases are exposed until they upgrade to a version that includes the corrective changes.
Risk and Exploitability
The CVSS score of 10 indicates a critical risk. The EPSS score of less than 1% suggests that, at present, the likelihood of exploitation is low but not null, meaning the vulnerability could still be taken advantage of by a determined adversary. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to engage with the Messaging System component, likely through crafted messages; however, the specific attack vector is inferred from the description and typical capabilities of sandbox escapes in messaging contexts.
OpenCVE Enrichment