Impact
A miscompilation in the JavaScript JIT engine that handles WebAssembly code can cause the generated machine code to execute unintended payloads, allowing an attacker to run arbitrary instructions with the privileges of the user and thereby compromising the confidentiality, integrity, and availability of the system. This weakness, identified as CWE-682, CWE-733 and CWE-843, effectively turns the browser into a potential execution platform for malicious code.
Affected Systems
Mozilla Firefox versions prior to 153 and the ESR 140.13 branch, and Mozilla Thunderbird versions prior to 153 and the ESR 140.13 branch are affected by this flaw.
Risk and Exploitability
The CVSS score of 9.8 classifies this flaw as Critical. The EPSS score of less than 1 % indicates a low but non‑zero likelihood of exploitation. Because the vulnerability is not listed in the CISA KEV catalog, no known active exploits have been reported yet. Based on the description, it is inferred that the likely attack vector is a remote attacker delivering malicious WebAssembly in a web page or a local attacker with a compromised browser profile.
OpenCVE Enrichment
Debian DLA
Debian DSA