Impact
This vulnerability arises from incorrect handling of boundary conditions in the audio and video playback component, allowing an attacker to overflow buffers that control memory. The flaw can lead to memory corruption and arbitrary code execution on the affected system, compromising confidentiality, integrity, and availability, and is classified as CWE‑119, CWE‑120, and CWE‑125.
Affected Systems
The flaw affects Mozilla Firefox and Mozilla Thunderbird. No specific version ranges are supplied, but the vendor has fixed the issue in Firefox 153 and Thunderbird 153. All earlier release versions are potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.1 reflects a high‑severity threat. The EPSS score of 0.00306 (0.306%) indicates a very low probability of exploitation in the near term, and the vulnerability is not listed in CISA's KEV catalog. Nonetheless, because the flaw permits arbitrary code execution, the likely attack vector would involve an attacker delivering a crafted media file or web page that triggers the vulnerable playback component, enabling the attacker to gain control of the victim’s system without additional privileges.
OpenCVE Enrichment