Impact
The vulnerability is a use‑after‑free in the Disability Access APIs component that allows an attacker to escape the sandbox and execute code outside the browser or email client. This can compromise confidentiality, integrity, or availability of the host system, and the weakness corresponds to CWE‑416 and CWE‑693.
Affected Systems
Mozilla Firefox releases earlier than version 153, including any ESR releases older than 115.38 and 140.13, and Mozilla Thunderbird releases earlier than version 153, including any ESR releases older than 140.13, all of which expose the accessibility feature.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, while the EPSS score of <1% shows a low probability of exploitation yet still high risk because the vulnerability enables full sandbox escape. Based on the description, it is inferred that a maliciously crafted web page or email containing specially constructed accessibility elements could trigger the use‑after‑free, thereby allowing a sandbox escape. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to deliver such content to a user who has the Accessibility feature enabled, and the attack would occur locally in the user's environment.
OpenCVE Enrichment
Debian DLA
Debian DSA