Impact
The vulnerability is an integer overflow (CWE-190) in the Graphics: ImageLib component, which can corrupt memory when processing image data. This flaw can allow an attacker to potentially execute arbitrary code or crash the application, leading to a loss of confidentiality, integrity, or availability of the affected system.
Affected Systems
The flaw affects Mozilla Firefox and Mozilla Thunderbird. Versions prior to 153 contain the unpatched code; Firefox 153 and Thunderbird 153 contain the fix.
Risk and Exploitability
The CVSS score of 9.8 marks this issue as critical. The EPSS score of less than 1% indicates a low but non‑zero probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Given that the overflow occurs while handling image files, the likely attack vector involves an attacker supplying a malicious image to the browser or email client to trigger the overflow.
OpenCVE Enrichment