Impact
The vulnerability stems from a miscompilation in the JavaScript Engine’s JIT component, which allows an attacker to cause the engine to execute incorrectly compiled code. This defect can lead to arbitrary code execution when a user visits a malicious web page or runs untrusted JavaScript, potentially compromising the client system’s confidentiality, integrity, and availability. The issue is classified as CWE‑843 (Type Confusion).
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. The flaw was fixed in Firefox version 153, Firefox Extended Support Release 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. All versions released before these require remediation.
Risk and Exploitability
The CVSS score of 9.8 and the EPSS score of less than 1% suggests exploitation is unlikely at the moment, and the flaw is not listed in the CISA KEV catalog. The likely attack vector involves malicious web content that exploits the JIT engine; attackers would need to entice a user to access a crafted page that triggers the miscompilation. The impact is potentially complete compromise of the affected client machine.
OpenCVE Enrichment
Debian DLA
Debian DSA