Impact
This vulnerability is a mitigation bypass in the PDF Viewer component of Mozilla Firefox and Thunderbird. It allows an attacker to circumvent the safeguards that normally protect PDF rendering. The flaw is classified as CWE‑693, indicating a security mechanism bypass, but the payload does not explicitly state that it enables code execution or other downstream effects. Users of an affected version might therefore face an elevated risk of unintended code execution when processing PDFs, depending on other system defenses and the content of the PDF.
Affected Systems
Mozilla Firefox and Thunderbird installations running versions prior to Firefox 153, Firefox ESR 140.13, Thunderbird 153, or Thunderbird ESR 140.13 are affected. Versions equal to or newer than those releases contain the fix and are not vulnerable.
Risk and Exploitability
The EPSS score is less than 1 %, indicating that real-world exploitation is currently rare. The CVSS score of 9.8 places this flaw in the critical severity range, showing a high potential impact if successfully exploited. The likelihood of an attack is inferred to involve a malicious PDF delivered to the client; based on the description, it is inferred that the attacker would need to convince a user to open the PDF. The vulnerability is not listed in CISA’s KEV catalog. While the high severity suggests significant risk, the low EPSS and lack of evidence for widespread exploitation imply that the immediate threat is limited, yet patching remains the prudent defense.
OpenCVE Enrichment
Debian DLA
Debian DSA