Impact
The vulnerability involves an invalid pointer that is used during the execution of a WebAssembly module by Firefox's JavaScript engine. Such a mis‑specified pointer can corrupt memory or trigger a crash. Public exploit code demonstrates that a malicious WebAssembly payload could trigger the vector, and if executed could corrupt memory, potentially enabling arbitrary code execution if an attacker can influence the WebAssembly that is executed.
Affected Systems
Both Mozilla Firefox and Thunderbird are affected; the advisory indicates that versions earlier than Firefox 152.0.6, Firefox ESR 140.13, and Thunderbird 140.13 are vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, while the EPSS score of less than 1 % implies a low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog, and no wild attacks have been reported. Public exploit code exists, but the modest CVSS and very low EPSS suggest that the practical risk remains low to moderate at this time.
OpenCVE Enrichment
Debian DLA
Debian DSA