Impact
An invalid pointer in Mozilla’s Security: PSM component can corrupt memory addresses when the component processes requests. The misuse of the pointer may allow an attacker to overwrite critical data in memory, potentially leading to arbitrary code execution or denial of service. The flaw triggers a NULL pointer dereference (CWE‑476) and an invalid pointer reference (CWE‑824).
Affected Systems
Mozilla Firefox and Mozilla Thunderbird versions prior to 153 are affected. Versions 152 and earlier of both applications contain the flaw, while version 153 and later incorporate the fix.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5 and an EPSS score of less than 1%, indicating that exploitation opportunities are currently rare. It is not listed in the CISA KEV catalog and no public exploit has been reported. The CVE does not specify the exact attack vector or prerequisites, so the conditions required for exploitation remain unspecified.
OpenCVE Enrichment