Impact
Memory safety bugs, classified as buffer overflows (CWE‑119) and memory corruption (CWE‑825), present in Firefox 152 (and Thunderbird 152) caused memory corruption and may allow an attacker to execute arbitrary code if enough effort is applied, as stated in the official description. The vulnerability was addressed in Firefox 153 and Thunderbird 153.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird users running the 152 release were affected by this memory safety issue. Both products contained the same bugs, and the fixes were applied in version 153 of each product. Users of the affected releases remain at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 9.8 classifies this vulnerability as critical, and the EPSS score of <1 % indicates a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog at present. Based on the nature of memory corruption, the likely attack vector is the delivery of malformed data to Thunderbird or Firefox, such as malicious attachments or corrupted content; this inference is made because the advisory does not specify a vector, but memory safety flaws typically arise from crafted inputs. The impact would be full control over the process, providing attackers with the ability to run arbitrary code on the victim’s machine.
OpenCVE Enrichment