Impact
The vulnerability is a use‑after‑free flaw in Firefox's graphics component that allows an attacker to escape the browser sandbox and execute arbitrary code outside the sandbox. This memory corruption bug can be triggered by specially crafted media or web content, potentially compromising the integrity of the host system.
Affected Systems
Mozilla Firefox is affected. The remedial releases that contain the fix are Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. Any user running a version prior to these patched releases remains vulnerable.
Risk and Exploitability
No CVSS score is provided and the EPSS is reported as unavailable, indicating that public exploitation data is sparse. The vulnerability is not listed in the CISA KEV catalog. Although the flaw provides high‑impact capabilities, the lack of observable active exploits suggests a low‑to‑moderate likelihood of exploitation under normal conditions. The attack vector is inferred to be remote, as the bug is triggered by content processed by the graphics engine.
OpenCVE Enrichment