Impact
An integer overflow flaw exists within Firefox and Thunderbird's JavaScript WebAssembly component. The overflow can be exploited to corrupt memory or alter control-flow information, potentially enabling arbitrary code execution or denial of service. The weakness is identified as CWE-190, indicating improper handling of integer calculations.
Affected Systems
Mozilla Firefox versions older than 153 and the ESR 140.13 branch, as well as Mozilla Thunderbird versions older than 153 and the ESR 140.13 branch, are impacted.
Risk and Exploitability
The CVSS score of 9.8 signals critical severity. Although the EPSS score is less than 1%, indicating a very low probability of exploitation at the time of analysis, the vulnerability is not listed in CISA KEV. It is inferred that the attack vector requires a malicious WebAssembly module delivered through a browser or email client, allowing an attacker to trigger the overflow and execute arbitrary code.
OpenCVE Enrichment
Debian DLA
Debian DSA