Impact
A use‑after‑free bug in Firefox’s DOM Content Processes component enables an attacker to escape the browser’s sandbox. The flaw arises when an object is freed while still in use, allowing malformed or malicious input to corrupt memory. If exploited, it can provide an attacker with the ability to execute arbitrary code outside the isolation boundaries normally imposed by the browser, potentially compromising the entire host system.
Affected Systems
This vulnerability affects all Mozilla Firefox releases older than Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. Any installation running a build prior to those patched versions is susceptible.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA KEV, indicating that no widespread exploitation has been reported yet. However, the nature of a use‑after‑free leading to sandbox escape suggests a high potential impact. The likely attack vector is through crafted web content or malicious extensions that can trigger the error in a content process. Given the severity implied by the description, rapid patching is recommended to mitigate possible exploitation.
OpenCVE Enrichment