Impact
A flaw in the Graphics component lets a malicious payload escape Firefox's sandbox, potentially allowing code to run with higher privileges than intended. The vulnerability is a classic privilege‑escalation issue that can compromise system integrity when exploited. It is a direct result of improper access control within the rendering engine, enabling the attacker to break containment.
Affected Systems
Mozilla Firefox is affected. The original article notes fixes in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17; earlier releases lack the patch. Exact vulnerable versions are not enumerated in the advisory, but any build older than those mentioned is likely at risk.
Risk and Exploitability
No EPSS score is provided, and the vulnerability is not currently listed in the CISA KEV catalog; nevertheless the inherent capabilities of a sandbox escape suggest a high impact. No publicly known exploits have been reported, but the attack vector is inferred to be content delivered via a web page or plugin that triggers the graphics subsystem, so web‑based attacks are the likely scenario.
OpenCVE Enrichment