Impact
Incorrect boundary conditions in the JavaScript: WebAssembly component can lead to a buffer overflow of type CWE-119 and an out-of-bounds write (CWE-787), enabling an attacker to execute arbitrary code. The vulnerability allows a malicious web page to trigger unchecked memory accesses within the WebAssembly engine, potentially allowing Remote Code Execution on the victim’s machine. The likelihood of Remote Code Execution is inferred from the described buffer overflow.
Affected Systems
This issue affects Mozilla Firefox versions prior to 153 and prior to 140.13 in the ESR branch, as well as Thunderbird prior to 153 and prior to 140.13 in the ESR branch. Security updates were released to address the flaw in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird ESR 140.13.
Risk and Exploitability
The CVSS score of 9.8 indicates an extreme risk level; the EPSS score is < 1%, meaning exploitation is currently rare but possible. The flaw is not included in the CISA KEV catalog. Based on the components involved, the likely attack vector is through a malicious web page containing WebAssembly payloads delivered to the user’s browser, which can trigger the boundary overflow and lead to Remote Code Execution. The vulnerability requires the user to have browser extensions or content that load WebAssembly code; therefore, normal browsing alone may not trigger exploitation without the attacker controlling the page.
OpenCVE Enrichment
Debian DLA
Debian DSA