Impact
Firefox contains a use‑after‑free bug in the DOM that allows an attacker to escape the sandbox used by content processes. If triggered, the vulnerability can lead to arbitrary code execution or escalation of privileges within the browser context. The flaw arises from improper memory deallocation and subsequent reuse, which is reflected in the CWE-416 classification.
Affected Systems
The vulnerability is present in Mozilla Firefox releases prior to ESR 153.4, Firefox 157, ESR 115.42, and ESR 140.17. Users running these affected builds, or older ESR releases, are exposed, while any edition that includes one of the listed fix versions provides protection.
Risk and Exploitability
The CVSS score is not provided, and the EPSS value is unavailable. The vulnerability is not listed in the CISA KEV catalog, so no active exploitation campaigns are publicly known. Nonetheless, sandbox escape represents a high‑impact flaw that could be leveraged wherever an adversary can supply or influence DOM content. Attackers would need to trigger the use‑after‑free, possibly via crafted web content, but details on the exact attack vector are not supplied in the data.
OpenCVE Enrichment