Impact
A use‑after‑free flaw in the DOM core and HTML component allows a sandbox escape, letting an attacker run code outside the intended isolation boundaries. This could compromise system integrity, enable privilege escalation, and expose sensitive information. The weakness is directly a use‑after‑free error.
Affected Systems
All Mozilla Firefox releases prior to the following patches are affected: Firefox ESR 115.42, Firefox ESR 140.17, Firefox ESR 153.4, and standard Firefox 157. Any older versions remain vulnerable.
Risk and Exploitability
Detailed CVSS or EPSS data for this issue are not publicly available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be content delivered by a malicious website or code executed within the browser’s sandbox. An attacker with sufficient access to trigger the use‑after‑free could escape the sandbox and execute arbitrary code on the host system, posing a high damage potential if the sandbox is the only isolation boundary in place.
OpenCVE Enrichment