Impact
Use after free occurs in the JavaScript garbage collector component in Mozilla Firefox and Thunderbird. The CVE description does not explicitly state the consequences; however, use‑after‑free flaws can lead to execution of arbitrary code or crashes, potentially impacting confidentiality, integrity, or availability. This potential impact is inferred from typical behavior of this class of vulnerability.
Affected Systems
The flaw affects all releases of Mozilla Firefox and Mozilla Thunderbird that were published before the patches. The vulnerability is fixed in Firefox 148, Firefox ESR 115.33 and 140.8, and in Thunderbird 148 and Thunderbird ESR 140.8.
Risk and Exploitability
The CVSS score is 9.8, indicating high severity, while the EPSS score is less than 1 %, suggesting a low likelihood of current exploitation. The CVE description does not specify an attack vector; it is inferred that malicious JavaScript delivered via a web page or crafted email could be a potential method. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA