Impact
A use‑after‑free flaw exists in the JavaScript WebAssembly engine that may allow an attacker to corrupt memory and potentially execute arbitrary code. The vulnerability originates from a race when an object is freed and reused, enabling a malicious script to craft a WebAssembly module that triggers the invalid memory reference. Successful exploitation could compromise the confidentiality, integrity, and availability of the user’s system by allowing code execution within the browser context.
Affected Systems
The flaw affects Mozilla Firefox browsers prior to the release of ESR 153.4 and the standard Firefox build 157. Users running earlier ESR or non‑ESR versions of Firefox are potentially vulnerable. The vulnerability is specific to the WebAssembly component of the JavaScript engine and does not affect other components or products beyond Firefox.
Risk and Exploitability
The CVSS score is not provided, and the EPSS score is unavailable, so the exact exploit likelihood is uncertain from the supplied data. However, because the issue involves a use‑after‑free in a browser feature widely used for web content, web pages delivering malicious WebAssembly modules could serve as a vector. The vulnerability is not yet listed in CISA’s KEV catalog, indicating no known widespread exploitation. The attack vector is likely remote via carefully crafted web content, and it requires an active user to open a tainted page. While the severity is potentially high, the lack of publicly disclosed exploits and absence from KEV suggest a moderate risk until further proof of concept becomes available.
OpenCVE Enrichment