Impact
Based on the description, it is inferred that a use‑after‑free flaw in the navigation component of the browser’s DOM can allow a malicious page to break the renderer sandbox and execute arbitrary code. The vulnerability falls under CWE‑416 and CWE‑825 and can lead to full system compromise, exposing all data, altering system state, or crashing the application.
Affected Systems
Mozilla products are impacted, including Firefox and the Thunderbird email client. Versions before Firefox 153, Firefox ESR 140.13, as well as Thunderbird 153 or Thunderbird 140.13, contain the flaw.
Risk and Exploitability
The CVSS score of 9.8 classifies it as Critical, and although the EPSS score is less than 1 %—indicating a very low probability of exploitation, it still represents a severe risk because of the potential for arbitrary code execution. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector would involve a malicious web page or email attachment delivered through the affected browser or mail client, requiring an active user session.
OpenCVE Enrichment
Debian DLA
Debian DSA