Impact
The vulnerability is a use‑after‑free error in the Storage: IndexedDB component. When a browser or Thunderbird client frees an object that is still referenced by a script or extension, the program may later read or write that memory. This flaw aligns with CWE‑416 and can allow an attacker to execute arbitrary code or crash the process, resulting in loss of confidentiality, integrity, or availability. The description does not specify the exact attack path, but the likely vector is a malicious web page or extension that triggers the use‑after‑free.
Affected Systems
Affected are all Mozilla Firefox releases up to and including Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, and all Mozilla Thunderbird releases up to and including Thunderbird 148 and Thunderbird ESR 140.8. Users of earlier ESR or non‑ESR builds before these versions are also vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score of less than 1 % shows a very low probability of exploitation at the time of this analysis, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers would need to deliver malicious content that accesses the vulnerable IndexedDB component, typically through the user's browser session. Because the flaw can lead to arbitrary code execution or a denial‑of‑service, the risk remains elevated until the patch is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA