Impact
This vulnerability arises from incorrect boundary checks in Mozilla’s cubeb audio/video component, which can lead to an out‑of‑bounds write and memory corruption. An attacker who can supply crafted audio or video data could potentially execute arbitrary code on the system or crash the application, compromising confidentiality and availability.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. The issue has been fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. Any older or unpatched installations remain vulnerable.
Risk and Exploitability
The CVSS score of 9.8 reflects a critical severity, while the EPSS score of < 1% indicates a low likelihood of exploitation at the time of analysis. The vulnerability is not yet listed in the CISA KEV catalog. Based on the description, it is inferred that the attack is local or requires the victim to consume malicious media; remote exploitation would need additional access or privilege escalation. The combination of high severity and low EPSS suggests that monitoring for unusual media handling or applying the fix promptly is essential.
OpenCVE Enrichment
Debian DLA
Debian DSA