Impact
The Graphics: ImageLib component has a flaw that permits the disclosure of sensitive information from the host, such as image data or metadata that should remain private. The vulnerability is classified as information disclosure and has a CVSS score of 7.5, indicating a high risk to confidentiality. An attacker who can obtain access to the exposed data could learn private content or system details that were not intended for public view.
Affected Systems
Mozilla Firefox releases older than version 153, ESR 115.38, and ESR 140.13, as well as Mozilla Thunderbird releases older than version 153 and 140.13, are vulnerable and should be upgraded to the specified patched releases or later to mitigate the risk.
Risk and Exploitability
The EPSS score is below 1%, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. The likely attack vector involves malicious content presented to the user, such as a crafted image file delivered via a web page or email attachment. The victim’s browser or mail client processes the image and inadvertently exposes private data, requiring the user to view the vulnerable content in a social‑engineering scenario.
OpenCVE Enrichment
Debian DLA
Debian DSA