Impact
Memory safety bugs were reported in Firefox ESR 140.12 and Firefox 152. The bugs caused memory corruption and, with enough effort, could potentially be exploited to run arbitrary code on an affected system. The issue has been addressed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Affected Systems
The vulnerable releases are Mozilla Firefox ESR 140.12, Firefox 152, and the corresponding Thunderbird products that share the same codebase. The flaw was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird ESR 140.13. Systems that have not applied these updates remain at risk.
Risk and Exploitability
The CVSS score of 9.8 classifies this vulnerability as critical, while the EPSS score of less than 1% indicates a low probability of exploitation in the near term. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is not explicitly documented; it is inferred that an attacker would need to trigger the memory corruption, likely by supplying crafted input or a malicious file to the browser or email client, but precise exploitation conditions are not disclosed.
OpenCVE Enrichment
Debian DLA
Debian DSA