Impact
A flaw in the JavaScript WebAssembly component allows an invalid pointer reference, which can corrupt memory and potentially enable arbitrary code execution from a web page. This vulnerability is identified by the erroneous pointer handling in the component’s implementation. The issue was addressed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17, meaning earlier builds remain susceptible.
Affected Systems
Any user running a version of Mozilla Firefox older than ESR 153.4, Firefox 157, or ESR 140.17 may be exposed. Those build versions lack the fix for the pointer misuse in WebAssembly and are therefore vulnerable.
Risk and Exploitability
The CVSS score is not provided and the EPSS score is unavailable, but the vulnerability has not yet been observed in the CISA KEV catalog. Because the flaw can lead to memory corruption, an attacker could potentially leverage it to bypass sandboxing and execute code within the browser context. While exploitation may require specific conditions and controlled input, the severity of a successful attack would be high, justifying proactive remediation.
OpenCVE Enrichment