Impact
The vulnerability is a use‑after‑free bug located in the Networking: Cache component of Mozilla Firefox. An attacker could potentially cause the browser to read or write memory after the associated object has already been freed, leading to memory corruption. Depending on the context, this flaw could be leveraged to execute arbitrary code or otherwise compromise the integrity and confidentiality of the victim system.
Affected Systems
This issue affects all Mozilla Firefox releases prior to the following security releases: Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. Users running earlier versions of these browsers on any supported operating system are potentially vulnerable.
Risk and Exploitability
No EPSS score is currently available, and the vulnerability is not listed in the CISA KEV catalog, but use‑after‑free flaws are known to have a high exploitation likelihood when a suitable trigger can be induced. In the absence of a published exploit, the risk is considered significant because the flaw resides in a core networking component and could allow remote attackers to exploit the bug by serving malicious content. The CVSS score is not provided, but the nature of the bug suggests a high severity potential.
OpenCVE Enrichment