Impact
An invalid pointer in the Disability Access APIs component permits a sandbox escape, enabling an attacker to execute arbitrary code with the privileges of the affected process. The flaw is a memory corruption issue involving use‑after‑free or out‑of‑bounds writes, classified under CWE‑119, CWE‑416, and CWE‑787. Successful exploitation results in full compromise of the application and potentially the host system.
Affected Systems
The vulnerability affects Mozilla Firefox and Mozilla Thunderbird releases older than version 153. Users running Firefox 152 or earlier, or Thunderbird 152 or earlier, are susceptible to this sandbox escape until they upgrade to the patched releases.
Risk and Exploitability
The CVSS base score of 10.0 underscores critical severity, while the EPSS score of less than 1 % indicates a very low but nonzero chance of exploitation. The flaw is not listed in the CISA KEV catalog. The most likely attack vector is local or logical, whereby an attacker delivers malicious content that the Disability Access APIs process, triggering the invalid pointer and escaping the sandbox. Because the defect lies in memory handling, exploitation typically requires the target to be running the vulnerable application and not under strict OS containment.
OpenCVE Enrichment