Impact
This vulnerability allows an attacker to escape the sandbox enforced by the browser or email client through incorrect boundary checks in the WebRender graphics component.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. The issue applies to all releases before Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8; versions at or beyond these patch levels contain the fix.
Risk and Exploitability
With a CVSS score of 10 the vulnerability is considered critical. The EPSS score indicates a very low exploitation probability. It is not yet present in CISA's KEV catalogue. The likely attack vector is remote, exploiting rendered web content from an untrusted source; the attacker would need to trick the rendering pipeline to access memory outside its bounds.
OpenCVE Enrichment
Debian DLA
Debian DSA