Impact
The vulnerability is a use‑after‑free in the Disability Access APIs component that permits an attacker to escape the sandbox of a web browser or email client and run arbitrary code, compromising confidentiality, integrity, and availability. The weakness falls under CWE‑416 (Use‑After‑Free) and CWE‑772 (Missing Release of Resource on Failure). The description indicates that the sandbox involved is that of the browser or email client; this is inferred because the component is part of Firefox and Thunderbird.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. All releases prior to Firefox 153, ESR 115.38, ESR 140.13, Thunderbird 153, and Thunderbird 140.13 are vulnerable. These older versions lack the fix and remain at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector involves triggering the use‑after‑free in the Disability Access APIs, potentially through specially crafted content or accessibility data. This inference is drawn from the phrasing of the advisory and the component involved.
OpenCVE Enrichment
Debian DLA
Debian DSA