Impact
This integer overflow occurs in Mozilla’s Audio/Video: Playback component. It was fixed in Firefox 153 and Thunderbird 153.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird versions earlier than 153 are affected. All releases before 153 contain the vulnerable implementation and have not yet received the patch that was released in product version 153.
Risk and Exploitability
The CVSS score of 9.8 reflects a very high severity, while the EPSS score of less than 1% signals a low but non‑zero probability that the vulnerability will be attacked in the wild. The issue is not listed in the CISA KEV catalog. Attackers would most likely deliver a specially crafted media file to the vulnerable playback component; no temporary workarounds are documented, so the only safe path is to apply the official fix.
OpenCVE Enrichment