Impact
This vulnerability is a sandbox escape in Mozilla Firefox's Graphics: WebRender component caused by incorrect boundary checks. An attacker could trigger it by supplying malicious graphic content, allowing code execution with the privileges of the browser process.
Affected Systems
All Firefox users running versions earlier than Firefox 157, Firefox ESR 115.42, Firefox ESR 140.17, or Firefox ESR 153.4 are affected. This includes every operating system supported by those releases.
Risk and Exploitability
No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require loading crafted graphics into the browser; once triggered, the sandbox escape could lead to arbitrary code execution.
OpenCVE Enrichment