Impact
The updated description confirms an integer overflow flaw in Mozilla’s Audio/Video component that can lead to memory corruption when handling crafted audio or video data. The vulnerability matches CWE‑190 and could allow a malicious file to overwrite memory while the component parses the payload.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird releases up to and including version 152 are affected, as the fix is applied in release 153. These products are distributed by Mozilla, so all installations of these browsers or email clients that have not yet been updated to 153 or later are vulnerable.
Risk and Exploitability
The CVSS score of 9.8 demonstrates a very high severity risk, while the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that a local or remote attacker might trigger the overflow by submitting a specially crafted audio or video stream that the component processes, potentially leading to memory corruption on the affected system.
OpenCVE Enrichment