Impact
A memory corruption flaw occurs when the widget component accesses memory after it has been freed. This use‑after‑free can allow an attacker to execute arbitrary code or crash the browser, leading to loss of confidentiality, integrity, or availability.
Affected Systems
Mozilla Firefox is affected, specifically Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. Users running versions older than those enumerated remain vulnerable.
Risk and Exploitability
The CVSS score is not provided, and the EPSS score is unavailable; the vulnerability is not listed in CISA KEV. The likely attack vector is through malicious web content that triggers the widget, enabling a remote attacker to exploit the use‑after‑free for code execution or denial of service.
OpenCVE Enrichment